VendorsRed Hatadvanced_cluster_management_for_kubernetesany version
Vulnerabilities

Red Hat Advanced Cluster Management any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-4740
Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation
Published 2026-04-07 · Modified
8.2EPSS 0.001
CVE-2026-44495
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Published 2026-06-11 · Modified
7.7EPSS 0.009
CVE-2025-57851
Mce: privilege escalation via excessive /etc/passwd permissions
Published 2026-04-08 · Analyzed
6.7EPSS 0.001
CVE-2025-6017
Rhacm: users with clusterreader role can see credentials from managed-clusters
Published 2025-07-02 · Analyzed
5.5EPSS 0.001
CVE-2020-25688
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.
Published 2020-11-23 · Modified
3.5EPSS 0.003