CVE-2026-4740
8.2Red Hat · Advanced Cluster Management
Improper validation of Kubernetes client certificate renewal in Red Hat Advanced Cluster Management allows a managed cluster administrator to forge certificates and escalate privileges across clusters.
Executive summary
A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management allows an authenticated managed cluster administrator to gain unauthorized control over additional managed clusters or the hub cluster.
Vulnerability
The vulnerability is an improper certificate validation flaw (CWE-295) within the Open Cluster Management technology. An attacker with managed cluster administrator privileges can forge client certificates during the renewal process, which the OCM controller incorrectly approves, leading to unauthorized cross-cluster control.
Business impact
The ability to perform cross-cluster privilege escalation represents a severe threat to multi-tenant container orchestration environments. By compromising the hub cluster, an attacker could gain full administrative control over the entire infrastructure, leading to total loss of data confidentiality, integrity, and availability. With a CVSS score of 8.2, this flaw poses a high risk to organizational security and compliance postures.
Remediation
Immediate Action: Update the affected Red Hat multicluster engine for Kubernetes components to the versions specified in the vendor security errata (RHSA-2026:11414, RHSA-2026:13542, RHSA-2026:13853, RHSA-2026:8218, and RHSA-2026:9848).
Proactive Monitoring: Review audit logs for anomalous certificate renewal requests or unexpected administrative activities originating from managed cluster service accounts.
Compensating Controls: Restrict administrative access to managed clusters to only trusted personnel and implement network segmentation to limit the reach of a potentially compromised cluster controller.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete cluster infrastructure takeover, organizations utilizing Red Hat Advanced Cluster Management must prioritize the application of the provided security updates. Administrators should verify their current version against the fixed release thresholds and apply patches immediately to prevent unauthorized cross-cluster escalation.
More Red Hat CVEs
Sources
Originally found and disclosed by Red Hat would like to thank Arnaud FEVRIER (Orange) for reporting this issue., per the CVE Program record.
- RHSA-2026:11414 Vendor advisory
- RHSA-2026:13542 Vendor advisory
- RHSA-2026:13853 Vendor advisory
- RHSA-2026:8218 Vendor advisory
- RHSA-2026:9848 Vendor advisory
- Vulnerability database entry
- blog.arfevrier.fr
- RHBZ#2450590 Issue tracker