Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Arnaud Fevrier

Researcher fromOrange
#32114of 55,125
8.2Total CVSS
Vulnerabilities · 1
PT-2026-30871
8.2
2026-04-07
Unknown · Kubernetes · CVE-2026-4740
Name of the Vulnerable Software and Affected Versions Open Cluster Management (OCM) (affected versions not specified) Description A flaw exists due to improper validation of Kubernetes client certificate renewal. This allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller, potentially leading to cross-cluster privilege escalation and control over other managed clusters, including the hub cluster. Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.