:rainbowCrow: on Nostr: > A flaw was found in the OpenShift Pipelines operator. The ...
https://access.redhat.com/security/cve/cve-2026-10840> A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.
Published at
2026-06-04 14:21:52 UTCEvent JSON
{
"id": "b725dfed3004312a80ab9959d35ba14563d944b166d3f96c682819345d4f0840",
"pubkey": "86b397086a130510861dd58f255fadeee1c47815185fa3bb628a06b4d6af31ac",
"created_at": 1780582912,
"kind": 1,
"tags": [
[
"proxy",
"https://infosec.exchange/@cR0w/116692281779225455",
"web"
],
[
"proxy",
"https://infosec.exchange/users/cR0w/statuses/116692281779225455",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/cR0w/statuses/116692281779225455",
"pink.momostr"
],
[
"-"
]
],
"content": "https://access.redhat.com/security/cve/cve-2026-10840\n\n\u003e A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.",
"sig": "465a9b4731cbc9c9cc8446d88a26d709db4c6a405566a8e4c07275f3e0af67b10a6d85dfbe2094fa5dab61fb937aaa515b5d68bde176975dac984dd870749517"
}