multicluster-engine/cluster-proxy-rhel9 vulnerabilities
CVEs whose affected-version data names the multicluster-engine/cluster-proxy-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-66794Critical· 9.3A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks…
▾ MidnightRed Hat · multicluster-engine/cluster-proxy-addon-rhel9EPSS 0.41%via NVD
CVE-2026-17107High· 8.5A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE)
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests wit…
▾ TwilightRed Hat · multicluster-engine/cluster-proxy-rhel9EPSS 0.35%via NVD