« Volver al listado

CVE-2026-10840

Estado: Pendiente de análisisAlta (7.1)—

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-10840",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-10840",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-04T13:11:57.092142Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:openshift_builds:1.7::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift Builds 1.7.3",
          "versions": [
            {
              "status": "unaffected",
              "version": "1783341609",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openshift-builds/openshift-builds-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_builds:1.8::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift Builds 1.8.1",
          "versions": [
            {
              "status": "unaffected",
              "version": "1784121108",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openshift-builds/openshift-builds-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-proxy-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-proxy-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-webhook-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-webhook-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-rhel8-operator",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-rhel9-operator",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:openshift_builds:1.7::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift Builds 1.7.3",
          "versions": [
            {
              "status": "unaffected",
              "version": "1783341609",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openshift-builds/openshift-builds-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_builds:1.8::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift Builds 1.8.1",
          "versions": [
            {
              "status": "unaffected",
              "version": "1784121108",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openshift-builds/openshift-builds-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-proxy-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-proxy-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-webhook-rhel8",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-operator-webhook-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-rhel8-operator",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_pipelines:1"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Pipelines",
          "packageName": "openshift-pipelines/pipelines-rhel9-operator",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-04T12:16:24.813",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36648",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:41036",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-10840",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484720",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36648",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:41036",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-10840",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484720",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10840.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate."
    },
    {
      "lang": "es",
      "value": "Una falla se encontró en el operador de OpenShift Pipelines. El ClusterRoleBinding tekton-scheduler-rolebinding otorga al grupo system:authenticated acceso de escritura a los recursos personalizados de Kueue y cert-manager a través del ClusterRole tekton-scheduler-role. Cuando los CRD de Kueue o cert-manager están presentes en el clúster, cualquier usuario autenticado puede interrumpir la programación de cargas de trabajo, manipular las prioridades de programación, eliminar objetos Workload de otros inquilinos o inducir a cert-manager a sobrescribir Secretos TLS, incluyendo el certificado predeterminado del controlador de entrada."
    }
  ],
  "lastModified": "2026-09-06T02:17:18.100",
  "sourceIdentifier": "secalert@redhat.com"
}