CVE-2026-4740

8.2

Red Hat · Advanced Cluster Management

Improper validation of Kubernetes client certificate renewal in Red Hat Advanced Cluster Management allows a managed cluster administrator to forge certificates and escalate privileges across clusters.

Executive summary

A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management allows an authenticated managed cluster administrator to gain unauthorized control over additional managed clusters or the hub cluster.

Vulnerability

The vulnerability is an improper certificate validation flaw (CWE-295) within the Open Cluster Management technology. An attacker with managed cluster administrator privileges can forge client certificates during the renewal process, which the OCM controller incorrectly approves, leading to unauthorized cross-cluster control.

Business impact

The ability to perform cross-cluster privilege escalation represents a severe threat to multi-tenant container orchestration environments. By compromising the hub cluster, an attacker could gain full administrative control over the entire infrastructure, leading to total loss of data confidentiality, integrity, and availability. With a CVSS score of 8.2, this flaw poses a high risk to organizational security and compliance postures.

Remediation

Immediate Action: Update the affected Red Hat multicluster engine for Kubernetes components to the versions specified in the vendor security errata (RHSA-2026:11414, RHSA-2026:13542, RHSA-2026:13853, RHSA-2026:8218, and RHSA-2026:9848).

Proactive Monitoring: Review audit logs for anomalous certificate renewal requests or unexpected administrative activities originating from managed cluster service accounts.

Compensating Controls: Restrict administrative access to managed clusters to only trusted personnel and implement network segmentation to limit the reach of a potentially compromised cluster controller.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete cluster infrastructure takeover, organizations utilizing Red Hat Advanced Cluster Management must prioritize the application of the provided security updates. Administrators should verify their current version against the fixed release thresholds and apply patches immediately to prevent unauthorized cross-cluster escalation.

More Red Hat CVEs

Sources

Originally found and disclosed by Red Hat would like to thank Arnaud FEVRIER (Orange) for reporting this issue., per the CVE Program record.