High severity7.4NVD Advisory· Published Aug 11, 2026· Updated Sep 21, 2026
CVE-2026-50237
CVE-2026-50237
Description
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
13- access.redhat.com/errata/RHSA-2026:54188nvd
- access.redhat.com/errata/RHSA-2026:54206nvd
- access.redhat.com/errata/RHSA-2026:54545nvd
- access.redhat.com/errata/RHSA-2026:54555nvd
- access.redhat.com/errata/RHSA-2026:54583nvd
- access.redhat.com/errata/RHSA-2026:54602nvd
- access.redhat.com/errata/RHSA-2026:54770nvd
- access.redhat.com/errata/RHSA-2026:56789nvd
- access.redhat.com/errata/RHSA-2026:56854nvd
- access.redhat.com/errata/RHSA-2026:56912nvd
- access.redhat.com/errata/RHSA-2026:60023nvd
- access.redhat.com/security/cve/CVE-2026-50237nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.