Red Hat Multicluster Engine for Kubernetes是美国Red Hat公司的一个管理Kubernetes多集群的引擎软件。 Red Hat Multicluster Engine for Kubernetes存在权限许可和访问控制问题漏洞,该漏洞源于managed-serviceaccount中ClusterRole授予过多权限,可能导致受感染的addon-manager pod读取所有命名空间中的任何secret,并批准任意证书签名请求,从而导致信息泄露和权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | any |
affected |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | any |
unaffected |
any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66780 | 9.9 CRITICAL | Submariner-operator: submariner-operator: flat broker trust model grants every spoke full |
| CVE-2026-12564 | 9.6 CRITICAL | Automation-controller: automation-controller: kubernetes service account token exfiltratio |
| CVE-2026-18963 | 9.1 CRITICAL | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentia |
| CVE-2026-66793 | 8.8 HIGH | Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary containe |
| CVE-2026-66783 | 8.2 HIGH | Submariner-operator: submariner-operator: arbitrary image override enables privileged code |
| CVE-2026-66782 | 7.8 HIGH | Submariner-operator: submariner-operator: broker api bearer token stored cleartext in cr s |
| CVE-2026-71365 | 7.7 HIGH | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-15571 | 7.3 HIGH | Keycloak-services: keycloak-services: predictable account-linking hash enables account tak |
| CVE-2026-66781 | 6.5 MEDIUM | Submariner-operator: submariner-operator: ipsec psk stored cleartext in submariner cr spec |
| CVE-2026-75032 | 6.3 MEDIUM | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder |
| CVE-2026-75485 | 5.5 MEDIUM | Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect redaction of |
| CVE-2026-73834 | 5.5 MEDIUM | Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redact |
| CVE-2026-19608 | 5.3 MEDIUM | Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy |
No comments yet