CVE-2026-9165: Red Hat Advanced Cluster Security 4

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

Affected products

  • Red Hat Red Hat Advanced Cluster Security 4
  • Red Hat Red Hat Advanced Cluster Security 4.9: before 1783357116 (fixed in 1783357116)
  • Red Hat Red Hat Advanced Cluster Security For Kubernetes 4.10: before 1783357140 (fixed in 1783357140)
  • Red Hat Red Hat Advanced Cluster Security For Kubernetes 4.11: before 1783352589 (fixed in 1783352589)

Published 2026-07-06. Last modified 2026-09-08.