RHACS Deployment Metadata Bypass via openshift.io Label
CVE-2026-10079 Published on July 31, 2026

Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

NVD

Vulnerability Analysis

CVE-2026-10079 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
LOW
Integrity Impact:
HIGH
Availability Impact:
NONE

Timeline

Reported to Red Hat.

Made public. 63 days later.

Weakness Type

Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.


Products Associated with CVE-2026-10079

Want to know whenever a new CVE is published for Red Hat Advanced Cluster Security? stack.watch will email you.

 

Affected Versions

Red Hat Advanced Cluster Security 4: Red Hat Advanced Cluster Security 4: Red Hat Advanced Cluster Security 4: