VendorsRed Hatadvanced_cluster_management_for_kubernetesall versions
Vulnerabilities

Red Hat Advanced Cluster Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-4740
Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation
Published 2026-04-07 · Modified
8.2EPSS 0.001
CVE-2022-3841
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
Published 2023-01-11 · Modified
7.8EPSS 0.002
CVE-2023-3027
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict properly to lookup content from the namespace where the policy was created.
Published 2023-06-05 · Modified
7.8EPSS 0.002
CVE-2026-44495
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Published 2026-06-11 · Modified
7.7EPSS 0.009
CVE-2026-71845
Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault()
Published 2026-08-11 · Modified
7.7EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Published 2022-03-18 · Modified
7.5EPSS 0.039
CVE-2025-14874
Nodemailer: nodemailer: denial of service via crafted email address header
Published 2025-12-18 · Modified
7.5EPSS 0.005
CVE-2022-3248
Openshift api admission checks does not enforce "custom-host" permissions
Published 2023-10-05 · Modified
7.5EPSS 0.004
CVE-2026-71474
Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response
Published 2026-08-11 · Modified
7.1EPSS 0.001
CVE-2026-71475
Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path
Published 2026-08-11 · Modified
6.8EPSS 0.005
CVE-2025-57851
Mce: privilege escalation via excessive /etc/passwd permissions
Published 2026-04-08 · Analyzed
6.7EPSS 0.001
CVE-2022-2238
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
Published 2022-09-01 · Modified
6.5EPSS 0.009
CVE-2020-25655
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.
Published 2020-11-09 · Modified
6.5EPSS 0.006
CVE-2026-71846
Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege
Published 2026-08-12 · Modified
6.5EPSS 0.001
CVE-2025-6017
Rhacm: users with clusterreader role can see credentials from managed-clusters
Published 2025-07-02 · Analyzed
5.5EPSS 0.001
CVE-2020-25688
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.
Published 2020-11-23 · Modified
3.5EPSS 0.003