๐Ÿ” CVE Alert

CVE-2026-10079

HIGH 8.5

Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection

CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

CWE CWE-345
Vendor red hat
Product red hat advanced cluster security 4
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat advanced cluster security 4

Be the first to know when new high vulnerabilities affecting red hat red hat advanced cluster security 4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected
Red Hat / Red Hat Advanced Cluster Security 4
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-10079 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2483158

Credits

This issue was discovered by Moritz Clasmeier (Red Hat).