Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.31% | — | Openfeature OperatorAI | 17/9/2026 | 24/9/2026 | The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME syntax to reference a FeatureFlagSource or InProcessConfiguration in another… | |
| Pendiente de análisis | Media (5.5) | 0.19% | — | Hawtio OperatorAI | 15/9/2026 | 17/9/2026 | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to… | |
| Pendiente de análisis | Media (6.3) | 0.49% | — | Hawtio OperatorAI | 15/9/2026 | 16/9/2026 | A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set… | |
| Pendiente de análisis | Alta (7.7) | 0.46% | — | Opentelemetry OperatorAI | 14/9/2026 | 25/9/2026 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as… | |
| Aplazada | Alta (7.7) | 0.21% | — | Redhat OpenshiftAIOpenai OperatorAI | 9/9/2026 | 9/9/2026 | A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended,… | |
| Rechazada | Sin puntuar | — | — | Hawtio-operatorAI | 8/9/2026 | 21/9/2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | |
| Pendiente de análisis | Crítica (9.9) | 0.39% | — | Hawtio-operatorAIRedhat OpenshiftAI | 8/9/2026 | 8/9/2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole… | |
| Pendiente de análisis | Alta (8.2) | 0.42% | — | Hawtio OperatorAI | 8/9/2026 | 8/9/2026 | A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The… | |
| Pendiente de análisis | Alta (7.7) | 0.31% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 10/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an… | |
| Pendiente de análisis | Crítica (9.6) | 0.21% | — | IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI | 4/9/2026 | 8/9/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch… | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Multicloud-operators SubscriptionAI | 20/8/2026 | 28/8/2026 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount… | |
| Pendiente de análisis | Alta (8) | 0.72% | — | Acm-operator-bundleAI | 19/8/2026 | 8/9/2026 | A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote… | |
| Pendiente de análisis | Alta (7.7) | 0.60% | — | Mce-operator-bundleAI | 19/8/2026 | 29/9/2026 | A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during… | |
| Pendiente de análisis | Crítica (9.9) | 0.55% | — | Search-v2-operatorAI | 19/8/2026 | 27/8/2026 | A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive… | |
| Pendiente de análisis | Crítica (9.1) | 0.71% | — | Search-v2-operatorAI | 19/8/2026 | 27/8/2026 | A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a… | |
| Pendiente de análisis | Media (6.5) | 0.58% | — | Submariner-operatorAI | 18/8/2026 | 29/9/2026 | A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an… | |
| Pendiente de análisis | Media (4.4) | 0.35% | — | Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI | 18/8/2026 | 3/9/2026 | A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker… | |
| Pendiente de análisis | Media (5.4) | 0.39% | — | Submariner OperatorAI | 18/8/2026 | 3/9/2026 | A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such… | |
| Pendiente de análisis | Alta (8.8) | 0.16% | — | Search-v2-operatorAI | 17/8/2026 | 27/8/2026 | A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters`… | |
| Pendiente de análisis | Crítica (9.9) | 0.69% | — | Multicloud-operators SubscriptionAI | 17/8/2026 | 29/9/2026 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the… | |
| Pendiente de análisis | Crítica (9.6) | 0.47% | — | Hashicorp Vault Secrets OperatorAI | 13/8/2026 | 28/8/2026 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel… | |
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Multicloud-operators SubscriptionAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret… | |
| Pendiente de análisis | Media (6.4) | 0.33% | — | Multicloud-operators ChannelAI | 12/8/2026 | 5/9/2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in… |