Executive brief
A security flaw was found in Open Cluster Management, a tool used to manage multiple Kubernetes environments from a single central hub. An administrator of one managed environment could exploit a weakness in how security certificates are renewed to trick the system into granting them access to other environments. This could allow an attacker to take control of the entire fleet of clusters, including the central management hub, potentially leading to a total compromise of data and operations across the organization.
Technical details
A vulnerability exists in the Open Cluster Management (OCM) controller's CertificateSigningRequest (CSR) validation logic. The 'csrRenewalReconciler' component fails to properly validate certificate renewal requests, specifically due to predictable cluster name prefix matching. An attacker with administrative access to a managed cluster can forge a client certificate that the OCM controller will incorrectly approve. This enables cross-cluster privilege escalation, allowing the attacker to gain unauthorized access to other managed clusters or the hub cluster itself. The issue was addressed in OCM versions 1.2.1, 1.1.3, and 1.0.1.
Affected products
- Open Cluster Management Open Cluster Management (OCM) < 1.2.1, < 1.1.3, < 1.0.1
- Red Hat Advanced Cluster Management for Kubernetes (ACM)
- Red Hat Multicluster Engine for Kubernetes (MCE)
Timeline
- 2026-02-02: disclosed: Vulnerability reported to Red Hat Security Team
- 2026-04-07: advisory: CVE-2026-4740 disclosed with a CVSS score of 8.2
- 2026-04-10: patched: Patches released in OCM 1.2.1, 1.1.3, and 1.0.1
References
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/security/cve/CVE-2026-4740
- https://blog.arfevrier.fr/open-cluster-management-cross-cluster-escape/
- https://bugzilla.redhat.com/show_bug.cgi?id=2450590
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4740.json