CVE-2026-10840: Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to kueue and cert-manager resources

Published Jun 4, 2026
·
Updated

A flaw was found in the OpenShift Pipelines operator (tektoncd/operator). The operator ships a ClusterRoleBinding (tekton-scheduler-rolebinding) that binds ClusterRole/tekton-scheduler-role to the system:authenticated group, granting all authenticated users cluster-wide create/update/patch/delete permissions on kueue.x-k8s.io resources (ResourceFlavor, Workload, WorkloadPriorityClass) and create/update permissions on cert-manager.io resources (Certificate, Issuer). When Kueue CRDs are present (e.g., via RHOAI), any authenticated user can disrupt cross-tenant workload scheduling by deleting ResourceFlavors, destroy other tenants' Workload objects, or tamper with scheduling priority. When cert-manager is installed, any authenticated user can create Certificate objects targeting arbitrary Secrets, including the default ingress controller's TLS Secret (openshift-ingress/router-certs-default), causing cert-manager to overwrite it with an attacker-influenced certificate. This confused deputy attack crosses authorization boundaries — the attacker cannot write Secrets directly but leverages cert-manager's ServiceAccount to do so. The RBAC objects are installed unconditionally even when the Tekton Scheduler feature is disabled.

Other sources

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

MITRE

Affected Software

1 affected component
Red Hat openshift-pipelines-operator

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict/adjust the ClusterRoleBinding named "tekton-scheduler-rolebinding" so it does not grant the "system:authenticated" group cluster-wide create/update/patch/delete permissions on "kueue.x-k8s.io" resources (ResourceFlavor, Workload, WorkloadPriorityClass) and create/update permissions on "cert-manager.io" resources (Certificate, Issuer).

    OpenShift Pipelines operator (tektoncd/operator) ClusterRoleBinding tekton-scheduler-rolebinding (binds tekton-scheduler-role to system:authenticated) = Remove or restrict binding so system:authenticated does not have write access

Event History

Jun 4, 2026
Data Sourced
via Red Hat·11:30 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Jul 28, 58407
Event
via MITRE·04:55 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-10840?

CVE-2026-10840 has a critical severity score of 9.6.

2

How do I fix CVE-2026-10840?

To fix CVE-2026-10840, modify the tekton-scheduler-rolebinding to limit access and avoid binding to the system:authenticated group.

3

What impact does CVE-2026-10840 have on my OpenShift environment?

CVE-2026-10840 allows all authenticated users to create, update, patch, or delete resources in kueue and cert-manager, which poses a security risk.

4

Which software is affected by CVE-2026-10840?

CVE-2026-10840 affects the Red Hat OpenShift Pipelines operator.

5

When was CVE-2026-10840 published?

CVE-2026-10840 was published on June 4, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203