CVE-2026-64927

MEDIUM CVSS 3.1: 6.4 EPSS 0.14%
Updated Aug 14, 2026
Red Hat
Parameter Value
CVSS 6.4 (MEDIUM)
Type CWE-639 (Authorization Bypass)
Vendor Red Hat
Public PoC No

A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas.

This could lead to unauthorized access to information or elevated privileges within the system.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat advanced cluster management for kubernetes 2