CVE-2026-10843: Red Hat Openshift Container Platform 4

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.

Affected products

  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-06-04. Last modified 2026-07-22.