PatchSiren cyber security CVE debrief
CVE-2026-4740 Red Hat CVE debrief
A flaw in Open Cluster Management (OCM) allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller, enabling cross-cluster privilege escalation. This issue affects Red Hat Advanced Cluster Management (ACM). The vulnerability allows an attacker to potentially gain control over other managed clusters, including the hub cluster, by exploiting improper validation of Kubernetes client certificate renewal. Defenders managing ACM deployments should assess their exposure and verify certificate validation practices to prevent potential cross-cluster privilege escalation and unauthorized access.
- Vendor
- Red Hat
- Product
- Multicluster Engine for Kubernetes
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-09-08
Who should care
Defenders managing Red Hat Advanced Cluster Management (ACM) deployments should assess their exposure to this vulnerability and verify their certificate validation practices to prevent potential cross-cluster privilege escalation and unauthorized access. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change
Why it matters
Defenders managing Red Hat Advanced Cluster Management (ACM) deployments should assess their exposure to this vulnerability and verify their certificate validation practices to prevent potential cross-cluster privilege escalation and unauthorized access.
- Potential cross-cluster privilege escalation
- Possible unauthorized access to managed clusters
- Need for verification of certificate validation practices
- Priority on applying Red Hat remediation
Technical summary
The vulnerability in Open Cluster Management (OCM) allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster, by exploiting improper validation of Kubernetes client certificate renewal. The issue affects Red Hat Advanced Cluster Management (ACM) and defenders should prioritize verifying exposure of ACM deployments, assessing certificate validation practices, and applying vendor remediation.
Defensive priority
Defenders should prioritize verifying exposure of ACM deployments, assessing certificate validation practices, and applying vendor remediation.
Recommended defensive actions
- Verify exposure of ACM deployments to this vulnerability
- Assess current certificate validation practices in OCM
- Apply remediation provided by Red Hat
- Monitor for suspicious certificate approval activities
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Red Hat has released several advisories related to this issue, including RHSA-2026:11414, RHSA-2026:13542, and RHSA-2026:13853. The vulnerability has been publicly disclosed and defenders should review the official advisories for affected scope, severity, and vendor guidance. Verification of certificate validation practices and applying Red Hat remediation are crucial steps in mitigating this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4740 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4740
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4740 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4740
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:11414
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13542
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13853
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:8218
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:9848
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-4740
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://blog.arfevrier.fr/open-cluster-management-cross-cluster-escape/
[email protected] - Exploit, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4740.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.