Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | — | — | External-secrets External Secrets OperatorAI | 6/10/2026 | 6/10/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was… | |
| En análisis | Crítica (9.9) | — | — | Dell Container Storage Modules OperatorAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Redhat Hypershift OperatorAI | 5/10/2026 | 6/10/2026 | A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Canonical Postgresql OperatorAI | 2/10/2026 | 6/10/2026 | The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which… | |
| Pendiente de análisis | Media (4.3) | 0.31% | — | Openfeature OperatorAI | 17/9/2026 | 24/9/2026 | The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME syntax to reference a FeatureFlagSource or InProcessConfiguration in another… | |
| Pendiente de análisis | Media (5.5) | 0.19% | — | Hawtio OperatorAI | 15/9/2026 | 17/9/2026 | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to… | |
| Pendiente de análisis | Media (6.3) | 0.49% | — | Hawtio OperatorAI | 15/9/2026 | 16/9/2026 | A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set… | |
| Pendiente de análisis | Alta (7.7) | 0.46% | — | Opentelemetry OperatorAI | 14/9/2026 | 25/9/2026 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as… | |
| Aplazada | Alta (7.7) | 0.21% | — | Redhat OpenshiftAIOpenai OperatorAI | 9/9/2026 | 9/9/2026 | A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended,… | |
| Pendiente de análisis | Crítica (9.9) | 0.39% | — | Hawtio-operatorAIRedhat OpenshiftAI | 8/9/2026 | 8/9/2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole… | |
| Pendiente de análisis | Alta (8.2) | 0.42% | — | Hawtio OperatorAI | 8/9/2026 | 8/9/2026 | A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The… | |
| Rechazada | Sin puntuar | — | — | Hawtio-operatorAI | 8/9/2026 | 21/9/2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | |
| Pendiente de análisis | Alta (7.7) | 0.31% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 10/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an… | |
| Pendiente de análisis | Crítica (9.6) | 0.21% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 8/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch… | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Multicloud-operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount… | |
| Pendiente de análisis | Alta (8) | 0.72% | — | Acm-operator-bundleAI | 19/8/2026 | 8/9/2026 | A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote… | |
| Pendiente de análisis | Alta (7.7) | 0.60% | — | Mce-operator-bundleAI | 19/8/2026 | 29/9/2026 | A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during… | |
| Pendiente de análisis | Crítica (9.9) | 0.55% | — | Search-v2-operatorAI | 19/8/2026 | 27/8/2026 | A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive… | |
| Pendiente de análisis | Crítica (9.1) | 0.71% | — | Search-v2-operatorAI | 19/8/2026 | 27/8/2026 | A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a… | |
| Pendiente de análisis | Media (4.4) | 0.35% | — | Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 3/9/2026 | A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker… | |
| Pendiente de análisis | Media (5.4) | 0.39% | — | Submariner OperatorAI | 18/8/2026 | 3/9/2026 | A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such… | |
| Pendiente de análisis | Media (6.5) | 0.58% | — | Submariner-operatorAI | 18/8/2026 | 28/9/2026 | A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an… | |
| Pendiente de análisis | Alta (8.8) | 0.16% | — | Search-v2-operatorAI | 17/8/2026 | 27/8/2026 | A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters`… | |
| Pendiente de análisis | Crítica (9.9) | 0.69% | — | Multicloud-operators SubscriptionAI | 17/8/2026 | 29/9/2026 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the… |