REDHAT-BUG-2484720: High severity Tekton OpenShift Pipelines Operator (tektoncd/operator) vulnerability

Published Jun 4, 2026
·
Updated

A flaw was found in the OpenShift Pipelines operator (tektoncd/operator). The operator ships a ClusterRoleBinding (tekton-scheduler-rolebinding) that binds ClusterRole/tekton-scheduler-role to the system:authenticated group, granting all authenticated users cluster-wide create/update/patch/delete permissions on kueue.x-k8s.io resources (ResourceFlavor, Workload, WorkloadPriorityClass) and create/update permissions on cert-manager.io resources (Certificate, Issuer). When Kueue CRDs are present (e.g., via RHOAI), any authenticated user can disrupt cross-tenant workload scheduling by deleting ResourceFlavors, destroy other tenants' Workload objects, or tamper with scheduling priority. When cert-manager is installed, any authenticated user can create Certificate objects targeting arbitrary Secrets, including the default ingress controller's TLS Secret (openshift-ingress/router-certs-default), causing cert-manager to overwrite it with an attacker-influenced certificate. This confused deputy attack crosses authorization boundaries — the attacker cannot write Secrets directly but leverages cert-manager's ServiceAccount to do so. The RBAC objects are installed unconditionally even when the Tekton Scheduler feature is disabled.

Affected Software

1 affected component
Tekton OpenShift Pipelines Operator (tektoncd/operator)

Event History

Jun 4, 2026
Data Sourced
via Red Hat·11:30 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2484720?

The severity of REDHAT-BUG-2484720 is high with a score of 7.

2

What flaw exists in REDHAT-BUG-2484720?

REDHAT-BUG-2484720 describes a flaw in the OpenShift Pipelines operator that allows all authenticated users to perform cluster-wide create/update/patch/delete operations.

3

How do I fix REDHAT-BUG-2484720?

To fix REDHAT-BUG-2484720, you should restrict the ClusterRoleBinding that binds the tekton-scheduler-role to the system:authenticated group.

4

What software is affected by REDHAT-BUG-2484720?

The affected software for REDHAT-BUG-2484720 is the Tekton OpenShift Pipelines Operator.

5

What impact does REDHAT-BUG-2484720 have on security?

The impact of REDHAT-BUG-2484720 is significant as it allows potential unauthorized access to perform critical operations on the Kubernetes cluster.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203