Security Advisory

CVE-2026-10843

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-04 12:04:49
Last updated 2026-07-15 01:23:19
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.