Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

514 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-76044] Arbitrary code execution due to a race condition in USB

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) This could potentially lead to the execution of arbitrary code outside of the browser's security sandbox, allowing the attacker to gain further control over the system. Exploitation requires a compromised renderer process and user interaction with a specially crafted HTML page, enabling a significant security bypass. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-368.

CVE-2026-76044
Unclassified
Aug 18, 2026
Critical9.1Red Hat

Critical [CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow bypass

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials. The Red Hat Product Security team has assessed the severity of this vulnerability as Critical, given that it can be exploited by an unauthenticated remote attacker without any user interaction. Successful exploitation allows an attacker to gain full access to any user account by bypassing the email verification step in the password recovery process. The vulnerability's root cause is improper state validation within the reset-credentials authentication flow. Weakness: CWE-640. Affected Red Hat products: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.4.15; Red Hat build of Keycloak 26.6; Red Hat build of Keycloak 26.6.6. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat fixing advisory: RHSA-2026:56519, RHSA-2026:56520, RHSA-2026:56524, RHSA-2026:56523.

CVE-2026-18963
Unclassified
Aug 18, 2026
Critical9.6Red Hat

Critical [CVE-2026-12564] Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY. The vulnerability is particularly impactful in AAP Cloud (managed service) environments where the Kubernetes control plane is managed by Red Hat and tenant isolation is a security boundary. On-premise deployments are also affected, though the impact is lower since the administrator already has access to the infrastructure. The vulnerable code path exists in all AAP versions that ship the hashivault credential plugin with kubernetes_role authentication support. Red Hat severity: Critical — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Ansible Automation Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12564
Unclassified
Aug 18, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-66795] CSR auto-approver does not validate certificate Subject or signerName (spoke→hub cluster-admin)

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster. This poses a significant risk to the overall security of the multicluster environment. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-295. Affected Red Hat products: multicluster engine for Kubernetes 2.1; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9. Red Hat fixing advisory: RHSA-2026:59557, RHSA-2026:59556, RHSA-2026:59593, RHSA-2026:59579, RHSA-2026:59558, RHSA-2026:59559.

CVE-2026-66795
Unclassified
Aug 17, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-71472] Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM

A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search CR is not properly validated before being used in a bash script and an SQL query. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potentially compromising the system. This is due to improper handling of untrusted input in the `WORK_MEM` string, leading to a complete compromise of the cluster's search service with cluster-wide impersonate privileges. Red Hat severity: Important — CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-71472
Unclassified
Aug 17, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-66792] IsClusterAdmin trusts user-settable annotations on managed clusters

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources. Critical: This flaw in Red Hat Advanced Cluster Management for Kubernetes allows a privileged user on a managed cluster to escalate privileges to cluster-admin. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-863. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17; Multicluster Global Hub; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Multicluster Global Hub; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-66792
Unclassified
Aug 17, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-68457] use opener credentials for FSCTL mutations

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and SET_COMPRESSION operate on an open SMB handle but call VFS xattr, fallocate or fileattr helpers with the current ksmbd worker credentials. Those helpers can revalidate inode permissions, ownership and LSM policy independently of the SMB handle access mask. Run each operation with the credentials captured in the target file when the handle was opened. Keep credential handling local to these single-file FSCTLs rather than applying session credentials to the complete IOCTL handler, which also contains handle-less and multi-handle operations. This vulnerability allows certain file system control (FSCTL) operations, specifically SET_SPARSE, SET_ZERO_DATA, and SET_COMPRESSION, to use incorrect credentials. Consequently, these operations can bypass the security checks established when the file was initially opened. This could enable a local attacker to perform unauthorized modifications to files, circumventing intended access restrictions. Red Hat severity: Important — CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-270. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-68457
Unclassified
Aug 15, 2026
Critical9.4Red Hat

Critical [CVE-2026-73653] Browser Mode provider commands bypass the file-access permission gate

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. A flaw was found in Vitest. A remote attacker, by sending specially crafted commands to the Browser Mode API, could bypass file access restrictions. This allows the attacker to read, create, overwrite, or delete arbitrary files on the system where Vitest is running, even when file write permissions are explicitly disabled. Red Hat severity: Critical — CVSS 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22. Affected Red Hat products: Red Hat Build of Podman Desktop. Red Hat lists Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Trusted Artifact Signer as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-73653
Unclassified
Aug 13, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-71471] Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector. ImageOverride` field. This allows the attacker to deploy an arbitrary container image across all managed clusters. The consequence is remote code execution (RCE), enabling the attacker to execute commands and potentially access sensitive information across the entire fleet of managed clusters. This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. This is due to the propagation of the `Collector. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L). Weakness: CWE-829. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more.

CVE-2026-71471
Unclassified
Aug 12, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-73501] ValidationHandler.Load Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler. Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0. This vulnerability allows a remote attacker to bypass authentication checks. Specifically, the system incorrectly handles missing authentication configurations, substituting them with a function that does not verify user credentials. This enables unauthorized access to protected resources that should require proper authentication, compromising the application's security. Red Hat rates this as Important rather than Critical because exploitation requires the target application to explicitly instantiate and load the ValidationHandler middleware instead of ValidateRequest() or the Validator middleware.

CVE-2026-73501
Red Hat Enterprise Linux
Aug 12, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster. The application-manager addon's ServiceAccount is granted broad wildcard permissions by default, enabling a malicious tenant to deploy arbitrary cluster-scoped resources. This significantly increases the blast radius beyond typical namespace boundaries. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-72508
Unclassified
Aug 12, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-70398] GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects. This is due to the GitOpsCluster controller writing secrets to an attacker-chosen namespace, bypassing existing security guards, leading to privilege escalation and circumvention of ArgoCD AppProject constraints. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-441. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-70398
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-72526] pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters. The Application propagation controller fails to validate the `ocm-managed-cluster` annotation, enabling an attacker to direct ManifestWorks to arbitrary managed clusters. This bypasses authorization, leading to significant privilege escalation across the managed environment. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-441. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-72526
Unclassified
Aug 12, 2026
Critical9.9Red Hat

Critical [CVE-2026-73213] Server-Side Request Forgery via incorrect IPv6 comparison

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0. A flaw was found in Coturn. An authenticated TURN client can bypass configured IP address restrictions due to an incorrect component-wise IPv6 comparison in the `addr_less_eq()` function. This allows the client to relay traffic to an IPv6 peer that should be denied, leading to a Server-Side Request Forgery (SSRF) vulnerability. Red Hat products do not ship Coturn. The community packages (Fedora, EPEL) ship Coturn 4.16.0 which includes the fix for this vulnerability. Red Hat severity: Critical — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-918.

CVE-2026-73213
Unclassified
Aug 11, 2026
Critical9.8Red Hat

Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws. Red Hat severity: Critical — CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644.

CVE-2026-10579
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets. The vulnerability stems from insufficient validation of the `spec.install.overrideJob` field, enabling injection of malicious Job specifications that run with the controller's highly privileged ServiceAccount, potentially exposing cluster-wide secrets and managed cluster access. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: multicluster engine for Kubernetes 2.1; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9. Red Hat fixing advisory: RHSA-2026:59557, RHSA-2026:59556, RHSA-2026:59593, RHSA-2026:59579, RHSA-2026:59558, RHSA-2026:59559.

CVE-2026-73268
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools. By creating a ClusterCurator resource with a mismatched name and namespace, an attacker can gain extensive permissions, including the ability to manage secrets and delete managed clusters, bypassing existing admission controls. This poses a significant risk to the overall cluster security and data integrity within Red Hat OpenShift environments deploying MCE. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-269. Affected Red Hat products: multicluster engine for Kubernetes 2.1; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9. Red Hat fixing advisory: RHSA-2026:59557, RHSA-2026:59556, RHSA-2026:59593, RHSA-2026:59579, RHSA-2026:59558, RHSA-2026:59559.

CVE-2026-73269
Unclassified
Aug 11, 2026
Critical9.9Red Hat

Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server

Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18948
Unclassified
Aug 10, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication

Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409, rhoai/odh-maas-api-rhel9:1787153683. Affected product named by the advisory: Red Hat OpenShift AI 3.4.

CVE-2026-14450
Unclassified
Aug 10, 2026
Critical9.9Red Hat

Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub

shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214.

CVE-2026-66801
Unclassified
Aug 10, 2026

← All vendors