Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation
Status: UPDATED
| Advisory ID: CVE-2026-4740
Key Details
| CVE | CVE-2026-4740 |
| CVSS Score / Version | 8.2 (High) / CVSS v3.1 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat advanced_cluster_management_for_kubernetes |
| Classified as | CWE-295 (Improper Certificate Validation) |
| Exploitation prediction (EPSS) | 0.15% probability of exploitation in the next 30 days (4% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.
What to Do
Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.
References