Known Vulnerabilities for Openshift by Redhat

Listed below are 10 of the newest known vulnerabilities associated with "Openshift" by "Redhat".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-86332 json A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource r... Not Provided 2026-09-07 2026-09-08
CVE-2026-81207 json IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully ... Not Provided 2026-09-10 2026-09-11
CVE-2026-80219 json A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient... Not Provided 2026-09-08 2026-09-11
CVE-2026-78234 json A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-servi... Not Provided 2026-09-08 2026-09-08
CVE-2026-71567 json In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without ... Not Provided 2026-08-17 2026-08-17
CVE-2026-71474 json A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can... Not Provided 2026-08-11 2026-09-05
CVE-2026-66788 json A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the des... Not Provided 2026-08-20 2026-09-03
CVE-2026-56160 json Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. Not Provided 2026-07-24 2026-08-07
CVE-2026-54100 json A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH... Not Provided 2026-06-22 2026-09-09
CVE-2026-54099 json A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-ap... Not Provided 2026-06-22 2026-09-09

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationRedhatOpenshift4.3.5
ApplicationRedhatOpenshift4.3
ApplicationRedhatOpenshift4.2.21
ApplicationRedhatOpenshift4.2
ApplicationRedhatOpenshift4.1.37
ApplicationRedhatOpenshift4.1
ApplicationRedhatOpenshift4.0
ApplicationRedhatOpenshift3.9
ApplicationRedhatOpenshift3.8
ApplicationRedhatOpenshift3.7
ApplicationRedhatOpenshift3.6
ApplicationRedhatOpenshift3.5
ApplicationRedhatOpenshift3.4
ApplicationRedhatOpenshift3.3.1.11
ApplicationRedhatOpenshift3.3
ApplicationRedhatOpenshift3.2.1.23
ApplicationRedhatOpenshift3.11.188-4
ApplicationRedhatOpenshift3.11
ApplicationRedhatOpenshift3.10
ApplicationRedhatOpenshift3.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report