Description
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.
Problem types
Execution with Unnecessary Privileges
Product status
Timeline
| 2026-04-26: | Reported to Red Hat. |
| 2026-04-26: | Made public. |
Credits
Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-10843
bugzilla.redhat.com/show_bug.cgi?id=2484738 (RHBZ#2484738)