chiprook
← Security
SecurityOctober 6, 2026, 08:55

HyperShift CVE-2026-101919: CVSS 8.8 tenant isolation bypass

OpenShift clusters running Multicluster Engine with HyperShift are affected by CVE-2026-101919 (CVSS 8.8, Red Hat Important). The ReconcileCredentials function copies a user-supplied kubeconfig Secret verbatim into the privileged control plane namespace, letting a tenant with basic namespace permissions execute code there.

HyperShift CVE-2026-101919: CVSS 8.8 tenant isolation bypass
#OpenShift#HyperShift#RedHat
Read next
Security

oc-mirror CVE-2026-75939: PGP signature check runs before the message is processed

Security

Red Hat warns AI is driving a surge in cyber threats and faster exploits

AI

Red Hat: 200M-parameter DeBERTa classifier nearly matches 35B model in AI guardrails

Security

Cloudflare fixes cross-tenant data exposure in Containers