CVE-2026-10843: Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws

Published Jun 4, 2026
·
Updated

A flaw was found in the Cloud Credential Operator (CCO) Mint-mode CredentialsRequest manifests shipped with OpenShift Container Platform for AWS. The CredentialsRequest specifications for the Image Registry, Machine API, Ingress Operator, and EBS CSI Driver request IAM policies with Resource: "" for destructive actions (S3 CreateBucket/DeleteBucket/PutObject/DeleteObject, EC2 TerminateInstances/RunInstances, Route53 ChangeResourceRecordSets, EC2 DeleteVolume/DeleteSnapshot). This grants the provisioned operator IAM credentials access to any AWS resource in the account, not just resources owned by the cluster. An attacker who obtains these credentials (via pod compromise, RBAC escalation, or Secret read) can perform destructive operations against unrelated AWS resources in the same account, including deleting S3 buckets, terminating EC2 instances, modifying DNS records in unrelated hosted zones, and deleting EBS volumes belonging to other workloads or clusters.

Other sources

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.

MITRE

Affected Software

2 affected components
Red Hat Cloud Credential Operator
Red Hat OpenShift Container Platform

Event History

Jun 4, 2026
Data Sourced
via Red Hat·11:55 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10843?

The severity of CVE-2026-10843 is rated as high with a score of 7.2.

2

What are the main concerns related to CVE-2026-10843?

CVE-2026-10843 allows account-wide IAM access on AWS due to excessively permissive IAM policies defined in the CredentialsRequest manifests.

3

How do I fix CVE-2026-10843?

To fix CVE-2026-10843, review and restrict the IAM policies in the CredentialsRequest manifests to ensure they do not use Resource: '*'.

4

Which components are affected by CVE-2026-10843?

CVE-2026-10843 impacts the Image Registry, Machine API, Ingress Operator, and EBS CSI Driver configurations in OpenShift Container Platform.

5

What should I do if I am using Red Hat OpenShift Container Platform?

If you are using Red Hat OpenShift Container Platform, it is recommended to assess your use of the Cloud Credential Operator and implement the necessary IAM policy restrictions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203