PT-2026-46191 · Red Hat+2 · Openshift Pipelines+2

·

CVE-2026-10840

·

Published

2026-06-04

·

Updated

2026-09-06

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions OpenShift Pipelines operator (affected versions not specified)
Description A flaw in the OpenShift Pipelines operator occurs because the tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources through the tekton-scheduler-role ClusterRole. If Kueue or cert-manager Custom Resource Definitions (CRDs) are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete Workload objects belonging to other tenants, or cause cert-manager to overwrite TLS Secrets, including the default ingress controller certificate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10840

Affected Products

Kueue
Openshift Pipelines
Cert-Manager