PT-2026-66735 · Red Hat · Red Hat Advanced Cluster Security For Kubernetes

·

CVE-2026-10079

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Advanced Cluster Security for Kubernetes (RHACS) (affected versions not specified)
Description A flaw exists when processing Kubernetes Deployments where the system replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permissions to create Deployments can set this label to "null", leading the system to treat the workload as having an empty UID, name, labels, and the "default" namespace. This results in a bypass of deploy-time policy detection and enforcement visibility, prevents correct persistence in Central, and disrupts violation reporting and compliance correlation for the affected deployment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10079

Affected Products

Red Hat Advanced Cluster Security For Kubernetes