Common Vulnerabilities and Exposures (CVE)

CVE-2026-4740

Aug 23, 2026 11:42:18 UTC

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client ce...

CVE-2026-16242

Aug 23, 2026 11:37:09 UTC

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not valid...

CVE-2026-50236

Aug 23, 2026 10:58:40 UTC

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full respons...

CVE-2026-42965

Aug 23, 2026 10:58:25 UTC

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. ...

CVE-2026-76606

Aug 23, 2026 10:48:31 UTC

Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

CVE-2026-76602

Aug 23, 2026 10:46:55 UTC

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

CVE-2026-76603

Aug 23, 2026 10:46:48 UTC

Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

CVE-2026-76571

Aug 23, 2026 10:46:28 UTC

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery()....

CVE-2026-76605

Aug 23, 2026 10:45:50 UTC

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

CVE-2026-76604

Aug 23, 2026 10:43:23 UTC

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.

CVE-2026-76607

Aug 23, 2026 10:41:10 UTC

Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.

CVE-2026-46579

Aug 23, 2026 10:30:38 UTC

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plai...

CVE-2026-50237

Aug 23, 2026 10:28:22 UTC

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing t...

CVE-2026-49332

Aug 23, 2026 10:28:08 UTC

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP fram...

CVE-2026-1784

Aug 23, 2026 10:13:47 UTC

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlle...