High severity8.2NVD Advisory· Published Apr 7, 2026· Updated Aug 13, 2026
CVE-2026-4740
CVE-2026-4740
Description
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
open-cluster-management.io/ocmGo | < 1.2.1 | 1.2.1 |
Affected products
3- cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:-:*:*:*:*:*:*:*
- ghsa-coords2 versionspkg:golang/open-cluster-management.io/ocmpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.2.1+ 1 more
- (no CPE)range: < 1.2.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
13- blog.arfevrier.fr/open-cluster-management-cross-cluster-escape/nvdExploitThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-4740nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-q4gv-pjmh-c735ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-4740ghsaADVISORY
- blog.arfevrier.fr/open-cluster-management-cross-cluster-escapeghsaWEB
- github.com/open-cluster-management-io/ocm/commit/9e70cc1e21a15239c81111062c0b37df4b5a8026ghsaWEB
- access.redhat.com/errata/RHSA-2026:11414nvd
- access.redhat.com/errata/RHSA-2026:13542nvd
- access.redhat.com/errata/RHSA-2026:13853nvd
- access.redhat.com/errata/RHSA-2026:8218nvd
- access.redhat.com/errata/RHSA-2026:9848nvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4740.jsonnvd
News mentions
0No linked articles in our index yet.