PT-2026-60566 · Unknown · Cert-Manager

CVE-2026-62290

·

Published

2026-07-16

·

Updated

2026-07-27

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions cert-manager versions 1.18.0 through 1.19.5 cert-manager versions 1.20.0 through 1.20.2
Description Namespace users can create Challenge resources under acme.cert-manager.io without admission validation that ties the Challenge to an Order, owner reference, or Issuer-selected solver. This allows an attacker to control Challenge.spec.solver values referencing a ClusterIssuer to bypass DNS01 solver selectors, including dnsZones, dnsNames, and matchLabels. Consequently, cert-manager may use ClusterIssuer DNS credentials for attacker-selected provider settings and DNS names, which can lead to the disclosure of X-Api-User and X-Api-Key headers for acme-dns.
Recommendations Update to version 1.19.6. Update to version 1.20.3.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CERT-MANAGER-2026-62290
CVE-2026-62290
GHSA-8RVJ-MM4H-C258

Affected Products

Cert-Manager