rhacm2/multicluster-operators-application-rhel9 vulnerabilities
CVEs whose affected-version data names the rhacm2/multicluster-operators-application-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-66792Critical· 9.9A flaw was found in the multicloud-operators-subscription component
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…
▾ MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.69%via NVD
CVE-2025-7195Medium· 6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…
▾ Sunlitoperator-framework · operator-sdkEPSS 0.22%via NVD