Security Advisory

CVE-2026-10840

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-04 12:04:42
Last updated 2026-07-26 11:30:34
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.