VYPR

OpenShift Pipelines

by Red Hat

CVEs (1)

  • CVE-2026-10840CriJun 4, 2026
    risk 0.62cvss 9.6epss

    A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are…