{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-10079/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-10079"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Advanced Cluster Security for Kubernetes"],"_cs_severities":["high"],"_cs_tags":["kubernetes","cloud-security","defense-evasion","cve-2026-10079"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-10079 affects Red Hat Advanced Cluster Security for Kubernetes (RHACS). The issue resides in how the platform processes Kubernetes Deployment objects. Specifically, RHACS uses the label 'openshift.io/encoded-deployment-config' to determine deployment identity metadata.\u003c/p\u003e\n\u003cp\u003eAn attacker with sufficient permissions to create Deployments in the cluster can explicitly set this label to \u0026quot;null\u0026quot;. This action forces the RHACS Central component to misinterpret the workload's identity, effectively assigning it an empty UID, name, and labels while defaulting the namespace to \u0026quot;default\u0026quot;. This misidentification causes a complete bypass of deploy-time policy detection and enforcement mechanisms. Furthermore, it results in a lack of visibility into the workload, prevents correct persistence within the security database, and breaks compliance correlation and violation reporting for the affected deployment. This vulnerability is critical for organizations relying on RHACS for automated security governance in multi-tenant or managed Kubernetes environments, as it allows for the deployment of non-compliant or malicious workloads without triggering platform-based alerting or blocking controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability is significant as it undermines the core security enforcement capabilities of the RHACS platform. By evading policy checks, attackers can deploy workloads that violate corporate security standards or contain malicious configurations without detection. This results in reduced visibility for security teams, broken compliance reporting, and the potential for persistent, unauthorized access within the container environment. The severity is reflected in the CVSS v3.1 base score of 8.5.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit current Kubernetes Deployment manifests for the presence of the 'openshift.io/encoded-deployment-config' label set to \u0026quot;null\u0026quot; or other obfuscated values.\u003c/li\u003e\n\u003cli\u003eImplement Kubernetes Admission Controllers to prevent users from injecting arbitrary metadata labels, specifically targeting the 'openshift.io/' prefix.\u003c/li\u003e\n\u003cli\u003eReview audit logs for unexpected Deployment creation events in non-standard namespaces, particularly those where metadata appears inconsistent with organizational naming conventions.\u003c/li\u003e\n\u003cli\u003eEnsure that RHACS Central is updated to the latest version as provided by Red Hat to remediate the metadata processing logic associated with CVE-2026-10079.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-31T11:37:32Z","date_published":"2026-07-31T11:37:32Z","id":"https://feed.craftedsignal.io/briefs/2026-07-rhacs-policy-bypass/","summary":"A vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows an authenticated user to bypass security policy enforcement by setting the 'openshift.io/encoded-deployment-config' label to 'null'.","title":"Red Hat Advanced Cluster Security Policy Bypass via Deployment Label Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-07-rhacs-policy-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-10079","version":"https://jsonfeed.org/version/1.1"}