VYPR
High severity7.2NVD Advisory· Published Jun 4, 2026· Updated Jun 4, 2026

CVE-2026-10843

CVE-2026-10843

Description

OpenShift Cloud Credential Operator flaw allows AWS account-wide IAM access beyond cluster scope, enabling cross-scope impact upon credential compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OpenShift Cloud Credential Operator flaw allows AWS account-wide IAM access beyond cluster scope, enabling cross-scope impact upon credential compromise.

Vulnerability

A flaw exists in the OpenShift Cloud Credential Operator (CCO) when using Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions, rather than being restricted to cluster-owned resources. This misconfiguration affects all versions of the affected component.

Exploitation

An attacker who compromises the operator credentials can leverage the account-wide scope granted to perform destructive actions outside the intended cluster boundaries. The vulnerability lies in the CCO's Mint-mode CredentialsRequest manifests which incorrectly grant broad IAM access.

Impact

Upon successful exploitation, an attacker can achieve cross-scope impact by performing destructive actions across the entire AWS account, not just on cluster-owned resources. This could lead to significant data loss, service disruption, or unauthorized modifications within the AWS environment.

Mitigation

This vulnerability is addressed in a fixed version of the OpenShift Cloud Credential Operator. Specific version details and release dates for the patch are available via the Red Hat advisory [1] and Bugzilla entry [2]. Users are advised to update to the patched version as soon as possible.

AI Insight generated on Jun 4, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.