Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 88%

Red Hat Security Advisory: Red Hat OpenShift Builds 1.8.1

0
High
Published: 07/16/2026 (07/16/2026, 15:12:39 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Releases of Red Hat OpenShift Builds 1.8.1

Affected software

Affected versions
>=1.7.3 <1.7.4Red HatRed Hat OpenShift BuildsRed Hat OpenShift Builds 1.7.3amd64registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:0ef830a815d07df60291e9c7b89a03dd40c0ceabfc3071f1fe188575f65a0542_amd64Red Hat OpenShift Builds 1.8.1registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:d8e57c472bdf507de76bf7e88dc9895ae32de6394895bee12a34ffb08232f49a_amd64Red Hat OpenShift Builds 1.7.1Red Hat OpenShift Builds 1.7.4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 18:59:40 UTC

Technical Analysis

CVE-2026-10840 is a vulnerability in the OpenShift Pipelines operator where the tekton-scheduler-rolebinding ClusterRoleBinding improperly grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. This misconfiguration allows any authenticated user to disrupt workload scheduling, tamper with scheduling priorities, delete workload objects belonging to other tenants, or cause cert-manager to overwrite TLS Secrets including the default ingress controller certificate. The vulnerable RBAC objects are deployed regardless of whether the Tekton Scheduler feature is enabled. The issue affects Red Hat OpenShift Builds versions >=1.7.3 and <1.7.4. The recommended remediation is to upgrade to version 1.7.4 or apply a manual patch to restrict the ClusterRoleBinding to a specific ServiceAccount, though the operator's reconciliation loop may revert manual changes.

Potential Impact

The vulnerability allows any authenticated user on the cluster to gain write privileges to critical custom resources related to workload scheduling and certificate management. This can result in disruption of workload scheduling, unauthorized modification or deletion of workloads belonging to other tenants, and overwriting of TLS secrets, potentially compromising cluster security and availability. The impact on confidentiality is rated none, integrity impact is low, and availability impact is high according to Red Hat's CVSS assessment.

Mitigation Recommendations

Red Hat recommends upgrading Red Hat OpenShift Builds from version 1.7.3 to 1.7.4, which contains the fix for this vulnerability. If the Tekton Scheduler feature is not in use, administrators can mitigate the issue by patching the tekton-scheduler-rolebinding ClusterRoleBinding to reference a specific ServiceAccount instead of the system:authenticated group. However, manual patches may be reverted by the operator's reconciliation loop, so verify that the operator does not revert this change or disable reconciliation for this object. Alternatively, the ClusterRoleBinding can be deleted if the Tekton Scheduler is not enabled. Always consult the official Red Hat advisory for detailed instructions and updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:36648
Cve Count
12
Additional Cves
["CVE-2026-27145","CVE-2026-33811","CVE-2026-39821","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39832","CVE-2026-39833","CVE-2026-39835","CVE-2026-42508","CVE-2026-46595"]
Cvss Version
3.1

Threat ID: 6a4e4ebac9d9e3dbe328516d

Added to database: 07/08/2026, 13:20:58 UTC

Last enriched: 08/14/2026, 18:59:40 UTC

Last updated: 08/22/2026, 13:39:43 UTC

Views: 92

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses