Executive brief
A security flaw was found in how Red Hat OpenShift manages cloud permissions on Amazon Web Services (AWS). The system grants administrative components broad, account-wide authority to delete or modify resources instead of limiting them to only the specific cluster they manage. If these credentials are stolen, an attacker could delete data, shut down servers, or modify DNS settings across the entire AWS account, potentially impacting other business applications and services beyond the OpenShift cluster.
Technical details
A vulnerability classified as Execution with Unnecessary Privileges (CWE-250) exists in the OpenShift Cloud Credential Operator (CCO) when using Mint-mode on AWS. The CredentialsRequest manifests for several components—including the Image Registry, Machine API, Ingress Operator, and EBS CSI Driver—request IAM policies using 'Resource: *' for destructive actions such as S3 DeleteBucket, EC2 TerminateInstances, and Route53 ChangeResourceRecordSets. While an attacker requires high privileges (such as pod compromise or Secret read access) to obtain these credentials, the lack of resource-level tagging or scoping allows them to perform actions against any resource within the AWS account. This bypasses the intended isolation between different clusters or workloads sharing the same AWS account.
Affected products
- Red Hat OpenShift Cloud Credential Operator Mint-mode on AWS
Timeline
- 2026-06-04: disclosed: Initial vulnerability report and CVE assignment
- 2026-06-04: advisory: Red Hat and NVD published advisory details