← All Advisories

Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation

Status: UPDATED  |  Advisory ID: CVE-2026-4740

Key Details

CVECVE-2026-4740
CVSS Score / Version8.2 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat advanced_cluster_management_for_kubernetes
Classified asCWE-295 (Improper Certificate Validation)
Exploitation prediction (EPSS)0.15% probability of exploitation in the next 30 days (4% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red Hatadvanced_cluster_management_for_kubernetes
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-4740
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-4740