PatchSiren

Red Hat CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Red Hat CVE published 2026-08-20

CVE-2026-67567

The multicloud-operators-subscription component has a critical vulnerability (CVE-2026-67567) that allows tenants to bypass security controls and deploy arbitrary resources across the cluster. This is due to the component's HelmRelease controller processing Helm chart templates using elevated ServiceAccount privileges without proper validation. Organizations using this component, especially those with mul [truncated]

MEDIUM Red Hat CVE published 2026-08-20

CVE-2026-66787

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malic [truncated]

LOW Red Hat CVE published 2026-08-20

CVE-2026-66785

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for these a [truncated]

HIGH Red Hat CVE published 2026-08-20

CVE-2026-77176

The flaw in Kata Containers allows a malicious host operator to exploit insufficient validation of CreateContainer mount and storage rules. This enables mounting arbitrary container-rootfs paths over sensitive host locations or provisioning arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input. Affected systems should review and enforce pr [truncated]

HIGH Red Hat CVE published 2026-08-20

CVE-2026-19611

A flaw in WildFly Elytron allows remote attackers to more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include non-ASCII characters, potentially leading to unauthorized access. This issue arises from the normalization of input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. Defenders responsible for pas [truncated]

HIGH Red Hat CVE published 2026-08-20

CVE-2026-73198

A flaw in FreeIPA allows a remote, unauthenticated attacker to cause a denial of service (DoS) condition by sending a large request body to the `/ipa/i18n_messages` endpoint, leading to memory exhaustion and degraded responsiveness. The vulnerability is caused by the lack of input validation on the request body size, allowing an attacker to send an arbitrarily large request. This can lead to memory exhaus [truncated]

HIGH Red Hat CVE published 2026-08-20

CVE-2026-73197

The CVE-2026-73197 vulnerability in FreeIPA allows remote, unauthenticated attackers to cause increased memory usage, slower request handling, and potential service disruption by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This issue has a CVSS score of 7.5 and is classified as HIGH severity. System administrators and security teams should be aware of the potential [truncated]

MEDIUM Red Hat CVE published 2026-08-20

CVE-2026-73196

A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value, leading to a denial of service due to excessive CPU and memory resource consumption. The vulnerability affects FreeIPA installations, particularly those with low-privilege user accounts. Evidence from available sources supports this assessment, indicating that improper size limit [truncated]

HIGH Red Hat CVE published 2026-08-20

CVE-2026-13097

A privilege escalation flaw was found in FreeIPA, which could allow a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise. The vulnerability exists due to the 389-ds directory server not properly acc [truncated]

CRITICAL Red Hat CVE published 2026-08-20

CVE-2026-11861

A critical vulnerability was found in FreeIPA, allowing Active Directory users to bypass authentication for FreeIPA services by impersonating a client name in the Ticket Granting Service (TGS). This flaw occurs because FreeIPA services do not verify Privilege Attribute Certificate (PAC) certificates. An authenticated Active Directory user could escalate their privileges within the FreeIPA domain.

HIGH Red Hat CVE published 2026-08-20

CVE-2026-18917

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of ser [truncated]

MEDIUM Red Hat CVE published 2026-08-20

CVE-2026-77014

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

NONE Red Hat CVE published 2026-08-20

CVE-2026-19582

A crafted PE file opened using binutils could lead to arbitrary code execution via a stack buffer overflow out of bounds write. The CVE record was published on 2026-08-20T05:16:27.987Z and was last modified on 2026-08-25T23:16:58.030Z. The NVD entry is currently Awaiting Analysis. This vulnerability affects binutils version 2.46.1 and prior versions. Successful exploitation requires user interaction and c [truncated]

MEDIUM Red Hat CVE published 2026-08-19

CVE-2026-76827

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T21:17:39.227Z and has not been modified since then. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. Cluster administrators, security teams, and users with access to search-indexer should be aware of this vuln [truncated]

HIGH Red Hat CVE published 2026-08-19

CVE-2026-75569

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distr [truncated]

CRITICAL Red Hat CVE published 2026-08-19

CVE-2026-66794

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T18:17:16.547Z and has not been modified since then. CVE-2026-66794 is a critical vulnerability in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. An unauthenticated attacker can manipulate URL path segments to proxy requests to arbitrary services across any managed clus [truncated]

HIGH Red Hat CVE published 2026-08-19

CVE-2026-76235

CVE-2026-76235 is a HIGH severity vulnerability in cockpit-ws with a CVSS score of 7.5. The vulnerability is caused by a memory leak flaw in the login page handler, which leaks a heap allocation on every unauthenticated request carrying a CockpitLang cookie. This allows a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service. System administrators and security teams s [truncated]

MEDIUM Red Hat CVE published 2026-08-18

CVE-2026-66783

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including [truncated]

MEDIUM Red Hat CVE published 2026-08-18

CVE-2026-66781

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T17:17:00.580Z and has not been modified since then. The Submariner operator stores IPsec pre-shared keys in an unencrypted format within the Submariner Custom Resource (CR). This flaw allows unauthorized parties to access and potentially decrypt network traffic flowing between Kubernetes clusters [truncated]

CRITICAL Red Hat CVE published 2026-08-18

CVE-2026-18963

A critical vulnerability was found in the reset-credentials flow of the keycloak-services component in Red Hat Build of Keycloak. This flaw allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link, potentially leading to full control over target user accounts. The vulnerability has a CVSS score of 9.1, indicating a cr [truncated]

MEDIUM Red Hat CVE published 2026-08-18

CVE-2026-73834

The must-gather component of Red Hat Advanced Cluster Management for Kubernetes contains a flaw that allows certain ACM wrapper Custom Resources with embedded Secret data to be collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive. This potentially exposes sensitive information to anyone with access to the archive. Th [truncated]

HIGH Red Hat CVE published 2026-08-18

CVE-2026-71365

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T16:18:16.157Z and has not been modified since then. The vulnerability is a server-side request forgery (SSRF) in AWX's webhook status callback mechanism. An admin user can forge a signed GitHub webhook payload with an arbitrary statuses_url, causing AWX to POST status updates to an attacker-contr [truncated]

CRITICAL Red Hat CVE published 2026-08-18

CVE-2026-12564

A critical vulnerability was found in the AAP Controller's HashiCorp Vault credential plugin in Red Hat Ansible Automation Platform 2.7. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to control plane namespaces with full pod CRUD and secret read permissions. This could lead to significant lateral movement and secret ex [truncated]

HIGH Red Hat CVE published 2026-08-18

CVE-2026-66793

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privileg [truncated]

CRITICAL Red Hat CVE published 2026-08-17

CVE-2026-66795

The managedcluster-import-controller's CSR auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR, potentially leading to privilege escalation and administrative credentials on the hub cluster. Organizations should focus o [truncated]

CRITICAL Red Hat CVE published 2026-08-17

CVE-2026-71472

The CVE-2026-71472 vulnerability exists in acm-search-v2-rhel9 due to improper validation of the WORK_MEM string provided in the Search Custom Resource (CR). This allows an authenticated attacker, such as a hub administrator or a Search CR editor, to inject malicious shell commands or SQL statements. Successful exploitation could lead to arbitrary code execution within the privileged postgres pod, potenti [truncated]

HIGH Red Hat CVE published 2026-08-17

CVE-2026-70495

The CVE-2026-70495 record indicates a flaw in the search-v2-operator component's `search-serviceaccount`, which has overly broad permissions. This allows impersonation of users and groups across the entire cluster if an attacker gains access to any pod running under this service account. The vulnerability class is related to improper permission management in Kubernetes components. Likely operational impac [truncated]

CRITICAL Red Hat CVE published 2026-08-17

CVE-2026-66792

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T19:16:34.237Z and has not been modified since then. The multicloud-operators-subscription component has a flaw that allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the abilit [truncated]

HIGH Red Hat CVE published 2026-08-17

CVE-2026-15218

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T14:20:19.357Z and has not been modified since then. The vulnerability involves excessive permissions for ServiceAccounts within Red Hat OpenShift AI. Compromising these ServiceAccounts could lead to full cluster administrator privileges. The excessive permissions stem from ServiceAccounts being g [truncated]

MEDIUM Red Hat CVE published 2026-08-14

CVE-2026-13002

The CVE-2026-13002 vulnerability is caused by a flow in the dnssec.c library, leading to an infinite loop in the dnsmasq service. An attacker who controls a DNSSEC-signed zone can exploit this vulnerability with a single crafted response to hang the dnsmasq process, killing all DNS resolution for its clients. The vulnerability has a CVSS score of 4.4 and a severity of MEDIUM. System administrators and sec [truncated]