CVE-2026-64927: Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64927?
CVE-2026-64927 has a medium severity score of 6.4.
How do I fix CVE-2026-64927?
To mitigate CVE-2026-64927, ensure proper permission settings are enforced for secret and configmap handling across namespaces.
What systems are affected by CVE-2026-64927?
CVE-2026-64927 affects the multicloud-operators-channel component that handles secrets across different namespaces.
What type of vulnerability is CVE-2026-64927?
CVE-2026-64927 is a confused deputy vulnerability allowing unauthorized manipulation of sensitive information.
Can exploitation of CVE-2026-64927 lead to data compromise?
Yes, exploitation of CVE-2026-64927 can lead to unauthorized modification and potential compromise of sensitive information.