Beveiligingsadvies

CVE-2026-10843

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-04 12:04:49
Laatst bijgewerkt 2026-07-15 01:23:19
Toegewezen door redhat
CVSS-score 7.2
Status PUBLISHED

Beschrijving

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.