multicluster-engine/managedcluster-import-controller-rhel9 vulnerabilities
CVEs whose affected-version data names the multicluster-engine/managedcluster-import-controller-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-66795Critical· 9.9A flaw was found in the managedcluster-import-controller
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. …
CVE-2026-16242Critical· 9.4A flaw was found in the Konnectivity proxy-server configuration for hosted control planes
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not va…
CVE-2025-7195Medium· 6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…