CVE-2026-10843: Red Hat Openshift Container Platform 4
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.
Affected products
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-06-04. Last modified 2026-07-22.