Database/Control plane, storage & DevOps
OpenShift Hive / MCE / ACM (vCenter credential exposure): vCenter credentials are written into the ClusterProvision
Impact
vCenter credentials are written into the ClusterProvision object after provisioning a vSphere cluster, so anyone with read access to those objects extracts them - a Kubernetes RBAC read grant becomes hypervisor admin.
Who can reach it
Any user or service account with read access to ClusterProvision objects in the management cluster.
What to do
Apply the Red Hat fix, then rotate the exposed vCenter credentials and audit who holds read on ClusterProvision. Rotation is mandatory here - the credentials are already at rest in etcd and in any cluster backup.
References
Related entries
- Jenkins (Git Parameter plugin): Git parameter value is not validated against the offered choicesCVE-2025-53652 · Jenkins (Git Parameter plugin)High
- Foreman: command injection in the errors:fetch_log rake task escalates a scoped sudo grant to full code executionCVE-2026-12540 · Foreman / Red Hat Satellite (foreman-rake errors:fetch_log task)High
- Foreman / Red Hat Satellite: shell injection via foreman-rake db:dump and db:import_dump pathsCVE-2026-12541 · Foreman / Red Hat Satellite (foreman-rake db:dump and db:import_dump tasks)High
- IBM AIX and PowerVM VIOS: improper authentication allows remote access to NFS exportsCVE-2026-16686 · IBM AIX / PowerVM VIOS NFS server (export authentication)High
- Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated APICVE-2026-5944 · Cisco Intersight Device Connector for Nutanix Prism CentralHigh
- OpenChoreo Backstage backend: hardcoded auth bypass exposes /api/* to unauthenticated callersCVE-2026-73666 · OpenChoreo Backstage backend (default auth policy)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.