---
id: CVE-2026-9165
title: A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
summary: >-
  A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS).
  Central does not limit the depth of GraphQL queries served on the
  authenticated GraphQL API. An authenticated user with a valid API token can
  send deeply neste…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: Red Hat
product: advanced-cluster-security/rhacs-main-rhel8
affected:
  - advanced-cluster-security/rhacs-main-rhel8 (all versions)
  - advanced-cluster-security/rhacs-main-rhel8 (all versions)
  - advanced-cluster-security/rhacs-main-rhel9 (all versions)
  - advanced-cluster-security/rhacs-main-rhel11 (all versions)
published: '2026-07-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:17:13.800'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9165'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:36207'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:36319'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:36625'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-9165'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2480505'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9165.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-9165'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9165'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-07T14:00:57.848857Z'
epss: 0.00548
epssPercentile: 0.44807
ingestedAt: '2026-07-19T01:26:59.159Z'
patched:
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - advanced_cluster_security_for_kubernetes 4.11
---

## Overview

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:36319** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.9 · released 2026-07-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:36319)
- **RHSA-2026:36625** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.10 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36625)
- **RHSA-2026:36207** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.11 · released 2026-07-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:36207)
- **Red Hat VEX** · Important · affected: Red Hat Advanced Cluster Security 4 · no fix planned: Red Hat Advanced Cluster Security 4 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9165.json)
