{"api_version":"1","generated_at":"2026-08-27T03:54:18+00:00","cve":"CVE-2026-64927","urls":{"html":"https://cve.report/CVE-2026-64927","api":"https://cve.report/api/cve/CVE-2026-64927.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64927","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64927"},"summary":{"title":"Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy","description":"A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-08-12 02:16:37","updated_at":"2026-08-26 23:17:15"},"problem_types":["CWE-639","CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514229","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2514229","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-64927","name":"https://access.redhat.com/security/cve/CVE-2026-64927","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60389","name":"https://access.redhat.com/errata/RHSA-2026:60389","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60390","name":"https://access.redhat.com/errata/RHSA-2026:60390","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60386","name":"https://access.redhat.com/errata/RHSA-2026:60386","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64927","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64927","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.13","version":"unaffected 1787259310 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.15","version":"unaffected 1787238600 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1787242099 * rpm","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-11T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-08-11T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64927","cve":"CVE-2026-64927","epss":"0.001430000","percentile":"0.038540000","score_date":"2026-08-26","updated_at":"2026-08-27 00:10:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-64927","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-12T15:08:50.881307Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-12T16:57:43.646Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.13::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-channel-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.13","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787259310","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.15::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-channel-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.15","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787238600","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-channel-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787242099","versionType":"rpm"}]}],"datePublic":"2026-08-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-639","description":"Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-26T22:06:14.607Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2026:60386","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60386"},{"name":"RHSA-2026:60389","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60389"},{"name":"RHSA-2026:60390","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60390"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-64927"},{"name":"RHBZ#2514229","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514229"}],"timeline":[{"lang":"en","time":"2026-08-11T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-08-11T00:00:00.000Z","value":"Made public."}],"title":"Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy","workarounds":[{"lang":"en","value":"Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-639: Authorization Bypass Through User-Controlled Key"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-64927","datePublished":"2026-08-12T01:12:08.474Z","dateReserved":"2026-08-11T17:40:07.973Z","dateUpdated":"2026-08-26T22:06:14.607Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 02:16:37","lastModifiedDate":"2026-08-26 23:17:15","problem_types":["CWE-639","CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-12T15:08:50.881307Z","id":"CVE-2026-64927","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64927","Ordinal":"1","Title":"Multicloud-operators-channel: multicloud-operators-channel: cros","CVE":"CVE-2026-64927","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64927","Ordinal":"1","NoteData":"A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system.","Type":"Description","Title":"Multicloud-operators-channel: multicloud-operators-channel: cros"}]}}}