PT-2026-46143 · Red Hat · Multicluster Engine For Kubernetes+7

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-10805

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-10805

Affected Products

Multicluster Engine For Kubernetes
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Jboss Enterprise Application Platform Expansion Pack
Red Hat Openshift Container Platform 4