Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.63%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI21/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's…
Pendiente de análisisCrítica (9.3)0.62%—Redhat Multicluster Engine FOR KubernetesAI19/8/202629/9/2026
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary…
Pendiente de análisisAlta (7.1)0.35%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI13/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable…
Pendiente de análisisMedia (5.8)0.40%—Redhat Multicluster EngineAI12/8/202629/9/2026
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept…
Pendiente de análisisCrítica (9.9)0.88%—Redhat Multicluster EngineAIRedhat Cluster Curator ControllerAI12/8/202629/9/2026
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the…
Pendiente de análisisCrítica (9.1)0.64%—Multicluster Engine FOR Kubernetes ClustercuratorAI5/8/20268/9/2026
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a…
Pendiente de análisisAlta (8.5)0.57%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI24/7/202629/9/2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds…
ModificadaMedia (5.5)0.20%—Redhat Multicluster Engine FOR Kubernetes30/4/20265/9/2026
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials…
AplazadaAlta (8.2)0.49%—Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI17/3/202521/8/2026
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials…