CVE-2026-10805: Red Hat Multicluster Engine For Kubernetes

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.

Affected products

  • Red Hat Multicluster Engine For Kubernetes
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 1:1.40.16-21.el8_10 (fixed in 1:1.40.16-21.el8_10)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 1:1.30.0-19.el8_4.1 (fixed in 1:1.30.0-19.el8_4.1)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 1:1.30.0-19.el8_4.1 (fixed in 1:1.30.0-19.el8_4.1)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 1:1.36.0-18.el8_6.1 (fixed in 1:1.36.0-18.el8_6.1)
  • Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 1:1.36.0-18.el8_6.1 (fixed in 1:1.36.0-18.el8_6.1)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 1:1.40.16-10.el8_8.1 (fixed in 1:1.40.16-10.el8_8.1)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 1:1.40.16-10.el8_8.1 (fixed in 1:1.40.16-10.el8_8.1)
  • Red Hat Red Hat Enterprise Linux 9: before 1:1.54.3-5.el9_8 (fixed in 1:1.54.3-5.el9_8)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 1:1.42.2-32.el9_2.1 (fixed in 1:1.42.2-32.el9_2.1)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 1:1.46.0-38.el9_4.1 (fixed in 1:1.46.0-38.el9_4.1)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 1:1.52.0-11.el9_6.1 (fixed in 1:1.52.0-11.el9_6.1)
  • Red Hat Red Hat Hardened Images
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-06-04. Last modified 2026-09-25.