CVE-2026-10843
Red Hat Red Hat OpenShift Container Platform 4
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.
- CVSS
- 7.2
- EPSS
- 0.33% 25.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.04