Skip to main content

CVE-2026-4740

CVE Details

Visit the official vulnerability details page for CVE-2026-4740 to learn more.

Initial Publication

04/07/2026

Last Update

04/07/2026

Third Party Dependency

open-cluster-management.io/ocm

NIST CVE Summary

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

CVE Severity

8.2

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Received

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.0-rc.1⚠️ Impacted⚠️ Impacted
1.0.7⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.