在 Kubernetes 多集群引擎(Multicluster Engine for Kubernetes)的 组件中发现了一个安全漏洞。该漏洞允许未经身份验证的攻击者(只要能够访问面向用户的路由),绕过身份验证和授权检查。通过操纵 URL 路径段,攻击者可以将请求代理到任何受管集群中的任意服务。这使得攻击者能够未经授权使用内部服务,而这些服务原本受到保护,可能导致信息泄露或进一步破坏集群环境。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70496 | 9.9 CRITICAL | Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v |
| CVE-2026-71470 | 9.1 CRITICAL | Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow uns |
| CVE-2026-76139 | 8.0 HIGH | Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@m |
| CVE-2026-75569 | 7.7 HIGH | Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mu |
| CVE-2026-76235 | 7.5 HIGH | Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie |
| CVE-2026-76827 | 6.8 MEDIUM | Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c |
| CVE-2026-18874 | 6.2 MEDIUM | Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml v |
| CVE-2026-75900 | 6.1 MEDIUM | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size |
| CVE-2026-76166 | 4.3 MEDIUM | Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast |
No comments yet