Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10840— Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to kueue and cert-manager resources

Quick assessment

Affected
Red Hat Red Hat OpenShift Builds 1.7.3
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Red Hat OpenShift Pipelines是美国红帽(Red Hat)公司的一个Kubernetes原生持续集成与持续交付平台。 Red Hat OpenShift Pipelines存在安全漏洞,该漏洞源于tekton-scheduler-rolebinding ClusterRoleBinding授予system:authenticated组对Kueue和cert-manager自定义资源的写访问权限,可能导致任何经过身份验证的用户破坏工作负载调度、篡改调度优先级、删除其他租户的Workl

CVSS 7.1 · High EPSS 0.22% · P11

Affected Version Matrix 8

VendorProduct Version RangeStatus
Red Hat OpenShift Pipelines any unaffected
any affected
any affected
any affected
any unaffected
any affected
Red Hat Red Hat OpenShift Builds 1.7.3 1783341609< * unaffected
Red Hat Red Hat OpenShift Builds 1.8.1 1784121108< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10840

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to kueue and cert-manager resources
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
Red Hat OpenShift Pipelines 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat OpenShift Pipelines是美国红帽(Red Hat)公司的一个Kubernetes原生持续集成与持续交付平台。 Red Hat OpenShift Pipelines存在安全漏洞,该漏洞源于tekton-scheduler-rolebinding ClusterRoleBinding授予system:authenticated组对Kueue和cert-manager自定义资源的写访问权限,可能导致任何经过身份验证的用户破坏工作负载调度、篡改调度优先级、删除其他租户的Workl
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat OpenShift Builds 1.7.3 1783341609 ~ * cpe:/a:redhat:openshift_builds:1.7::el9
Red Hat Red Hat OpenShift Builds 1.8.1 1784121108 ~ * cpe:/a:redhat:openshift_builds:1.8::el9
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1
Red Hat OpenShift Pipelines - cpe:/a:redhat:openshift_pipelines:1

II. Public POCs for CVE-2026-10840

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10840

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-10840 (3)

Other References for CVE-2026-10840 (1)

Same Patch Batch · Red Hat · 2026-06-04 · 3 CVEs total

CVE-2026-10843 7.2 HIGH Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide i
CVE-2026-10805 6.7 MEDIUM Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhcli

IV. Related Vulnerabilities

V. Comments for CVE-2026-10840

No comments yet


Leave a comment