Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-10840 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-06-04 |
| Vendor | Red Hat |
| Product | OpenShift Pipelines |
| CVSS Score | 9.6 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants’ Workload objects, or induce cert-manager to overwrite TLS Secrets including the defa…
Required Actions
Apply vendor patches or mitigations as soon as available.
Who Is Affected?
This vulnerability affects OpenShift Pipelines by Red Hat. Check if your organization uses this software and requires updates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
