216.73.217.22

CVE-2026-10840

· Published 04/06/2026 12:16 · Modified 04/06/2026 15:35

Labels: CVE-2026-10840 2026-06-04CVE-2026-10840CWE-732[email protected]

Essential information

Published
04/06/2026 12:16
Modified
04/06/2026 15:35
Author
Creator
CVSS
9.6 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

CVSS metrics

Description

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
redhat / openshift pipelines operator cpe:2.3:a:redhat:openshift_pipelines_operator:*:*:*:*:*:*:*:*
redhat / kueue cpe:2.3:a:redhat:kueue:*:*:*:*:*:*:*:*
redhat / cert-manager cpe:2.3:a:redhat:cert-manager:*:*:*:*:*:*:*:*

References