Red Hat Advanced Cluster Security 4: insufficient authenticity check
High8.5CVE-2026-10079 · Published Jul 31, 2026 · updated Aug 3, 2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Advanced Cluster Security 4 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-345
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 31 | Red Hat Ansible Automation Platform 2: improper certificate validation | High8.2 | No fix yet |
| Jul 31 | Red Hat gnome-remote-desktop as shipped: resource exhaustion | High7.5 | No fix yet |
| Jul 31 | A flaw was found in 389 Directory Server | High7.5 | No fix yet |
| Jul 31 | Red Hat: buffer overflow | High7.5 | No fix yet |
| Jul 31 | Red Hat SAML protocol implementation of Keycloak: improper input validation | Low3.4 | No fix yet |
| Jul 31 | Red Hat TokenManager: missing authorization | Medium4.2 | No fix yet |