PT-2026-60566 · Unknown · Cert-Manager
CVE-2026-62290
·
Published
2026-07-16
·
Updated
2026-07-27
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
cert-manager versions 1.18.0 through 1.19.5
cert-manager versions 1.20.0 through 1.20.2
Description
Namespace users can create Challenge resources under acme.cert-manager.io without admission validation that ties the Challenge to an Order, owner reference, or Issuer-selected solver. This allows an attacker to control
Challenge.spec.solver values referencing a ClusterIssuer to bypass DNS01 solver selectors, including dnsZones, dnsNames, and matchLabels. Consequently, cert-manager may use ClusterIssuer DNS credentials for attacker-selected provider settings and DNS names, which can lead to the disclosure of X-Api-User and X-Api-Key headers for acme-dns.Recommendations
Update to version 1.19.6.
Update to version 1.20.3.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cert-Manager