PT-2026-66735 · Red Hat · Red Hat Advanced Cluster Security For Kubernetes
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Advanced Cluster Security for Kubernetes (RHACS) (affected versions not specified)
Description
A flaw exists when processing Kubernetes Deployments where the system replaces deployment identity metadata based on the
openshift.io/encoded-deployment-config label. A user with permissions to create Deployments can set this label to "null", leading the system to treat the workload as having an empty UID, name, labels, and the "default" namespace. This results in a bypass of deploy-time policy detection and enforcement visibility, prevents correct persistence in Central, and disrupts violation reporting and compliance correlation for the affected deployment.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Advanced Cluster Security For Kubernetes