Red hat advanced cluster management for kubernetes 2.14
This hub aggregates every CVE we track for Red hat advanced cluster management for kubernetes 2.14, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
32
CVEs tracked
10
Critical
10
High
0
In CISA KEV
Severity distribution
MEDIUM12HIGH10CRITICAL10
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
30
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat advanced cluster management for kubernetes 2.14.
- CVE-2026-89060Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references7.7
- CVE-2026-73137Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secret exfiltration via helmrelease.repo.secretref.namespace7.7
- CVE-2026-67567Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction9.9
- CVE-2026-76827Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)6.8
- CVE-2026-76139Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials8.0
- CVE-2026-70496Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork9.9
- CVE-2026-18874Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription6.2
- CVE-2026-71470Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa9.1
- CVE-2026-66780Submariner-operator: broker serviceaccount secret (token + ca) logged in full at trace verbosity6.5
- CVE-2026-66781Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication5.4
- CVE-2026-75485Must-gather: /tmp/kubeconfig retention5.5
- CVE-2026-73834Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redaction5.5
- CVE-2026-66793Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spoke8.8
- CVE-2026-71472Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem9.1
- CVE-2026-70495Search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters8.8
Product normalization is registry-driven with AI assist and human review. How it works