Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. https://access.redhat.com/security/cve/cve-2026-10840

https://access.redhat.com/security/cve/cve-2026-10840

Scheduled Pinned Locked Moved Uncategorized
19 Posts 8 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote last edited by
    #1

    Link Preview Image
    cve-details

    favicon

    (access.redhat.com)

    A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

    wdormann@infosec.exchangeW spartan_1986@infosec.exchangeS 2 Replies Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      Link Preview Image
      cve-details

      favicon

      (access.redhat.com)

      A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

      wdormann@infosec.exchangeW This user is from outside of this forum
      wdormann@infosec.exchangeW This user is from outside of this forum
      wdormann@infosec.exchange
      wrote last edited by
      #2

      @cR0w
      https://www.youtube.com/watch?v=aW2LvQUcwqc

      cr0w@infosec.exchangeC zackwhittaker@mastodon.socialZ tindrasgrove@infosec.exchangeT 3 Replies Last reply
      0
      • wdormann@infosec.exchangeW wdormann@infosec.exchange

        @cR0w
        https://www.youtube.com/watch?v=aW2LvQUcwqc

        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchange
        wrote last edited by
        #3

        @wdormann I don't have YouTube but searching the link looks like the Rockwell Retroencabulator video?

        J wdormann@infosec.exchangeW 2 Replies Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          @wdormann I don't have YouTube but searching the link looks like the Rockwell Retroencabulator video?

          J This user is from outside of this forum
          J This user is from outside of this forum
          jackryder@infosec.exchange
          wrote last edited by
          #4

          @cR0w @wdormann It's a video of a guy talking a bunch of science stuff.

          The fictional Retro Encabulator device, which uses six hydrocoptic marzel vanes and an ambifacient lunar wane shaft to prevent unwanted side fumbling. We can't believe the salesman was able to keep a straight face.

          cr0w@infosec.exchangeC 1 Reply Last reply
          0
          • J jackryder@infosec.exchange

            @cR0w @wdormann It's a video of a guy talking a bunch of science stuff.

            The fictional Retro Encabulator device, which uses six hydrocoptic marzel vanes and an ambifacient lunar wane shaft to prevent unwanted side fumbling. We can't believe the salesman was able to keep a straight face.

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote last edited by
            #5

            @jackryder @wdormann Ah. Yeah, that one's a classic.

            J 1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              @jackryder @wdormann Ah. Yeah, that one's a classic.

              J This user is from outside of this forum
              J This user is from outside of this forum
              jackryder@infosec.exchange
              wrote last edited by
              #6

              @cR0w @wdormann He looks like Chris Hansen from an alternative timeline where he went "Sales guy" instead of "Have a seat..."

              cr0w@infosec.exchangeC 1 Reply Last reply
              0
              • J jackryder@infosec.exchange

                @cR0w @wdormann He looks like Chris Hansen from an alternative timeline where he went "Sales guy" instead of "Have a seat..."

                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchangeC This user is from outside of this forum
                cr0w@infosec.exchange
                wrote last edited by
                #7

                @jackryder @wdormann They're the same picture.

                J 1 Reply Last reply
                0
                • cr0w@infosec.exchangeC cr0w@infosec.exchange

                  @jackryder @wdormann They're the same picture.

                  J This user is from outside of this forum
                  J This user is from outside of this forum
                  jackryder@infosec.exchange
                  wrote last edited by
                  #8

                  @cR0w @wdormann it's creepy!
                  Like, are we sure it isn't Chris?

                  watches for the 8millionth time

                  1 Reply Last reply
                  0
                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                    @wdormann I don't have YouTube but searching the link looks like the Rockwell Retroencabulator video?

                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchangeW This user is from outside of this forum
                    wdormann@infosec.exchange
                    wrote last edited by
                    #9

                    @cR0w
                    "Don't have YouTube"...
                    YouTube is a website?

                    cr0w@infosec.exchangeC ajn142@infosec.exchangeA fritzadalis@infosec.exchangeF 3 Replies Last reply
                    0
                    • wdormann@infosec.exchangeW wdormann@infosec.exchange

                      @cR0w
                      "Don't have YouTube"...
                      YouTube is a website?

                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchange
                      wrote last edited by
                      #10

                      @wdormann Sorry, I mean it's blocked on my network. Intentionally.

                      cr0w@infosec.exchangeC 1 Reply Last reply
                      0
                      • wdormann@infosec.exchangeW wdormann@infosec.exchange

                        @cR0w
                        "Don't have YouTube"...
                        YouTube is a website?

                        ajn142@infosec.exchangeA This user is from outside of this forum
                        ajn142@infosec.exchangeA This user is from outside of this forum
                        ajn142@infosec.exchange
                        wrote last edited by
                        #11

                        @wdormann @cR0w I assume they mean it's blocked on their network?

                        1 Reply Last reply
                        0
                        • cr0w@infosec.exchangeC cr0w@infosec.exchange

                          @wdormann Sorry, I mean it's blocked on my network. Intentionally.

                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchange
                          wrote last edited by
                          #12

                          @wdormann Unlike Reddit who blocks me.

                          cr0w@infosec.exchangeC 1 Reply Last reply
                          0
                          • cr0w@infosec.exchangeC cr0w@infosec.exchange

                            @wdormann Unlike Reddit who blocks me.

                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchange
                            wrote last edited by
                            #13

                            @wdormann

                            Link Preview Image
                            1 Reply Last reply
                            0
                            • wdormann@infosec.exchangeW wdormann@infosec.exchange

                              @cR0w
                              https://www.youtube.com/watch?v=aW2LvQUcwqc

                              zackwhittaker@mastodon.socialZ This user is from outside of this forum
                              zackwhittaker@mastodon.socialZ This user is from outside of this forum
                              zackwhittaker@mastodon.social
                              wrote last edited by
                              #14

                              @wdormann @cR0w if you haven't seen the Rick & Morty "plumbus" video, it has a similar vibe. always cracks me up.

                              1 Reply Last reply
                              0
                              • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                @cR0w
                                "Don't have YouTube"...
                                YouTube is a website?

                                fritzadalis@infosec.exchangeF This user is from outside of this forum
                                fritzadalis@infosec.exchangeF This user is from outside of this forum
                                fritzadalis@infosec.exchange
                                wrote last edited by
                                #15

                                @wdormann @cR0w
                                I mean I tell people I don't have a phone... when I'm standing in front of them looking at my phone.

                                wdormann@infosec.exchangeW 1 Reply Last reply
                                0
                                • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

                                  @wdormann @cR0w
                                  I mean I tell people I don't have a phone... when I'm standing in front of them looking at my phone.

                                  wdormann@infosec.exchangeW This user is from outside of this forum
                                  wdormann@infosec.exchangeW This user is from outside of this forum
                                  wdormann@infosec.exchange
                                  wrote last edited by
                                  #16

                                  @FritzAdalis @cR0w

                                  1 Reply Last reply
                                  0
                                  • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                    @cR0w
                                    https://www.youtube.com/watch?v=aW2LvQUcwqc

                                    tindrasgrove@infosec.exchangeT This user is from outside of this forum
                                    tindrasgrove@infosec.exchangeT This user is from outside of this forum
                                    tindrasgrove@infosec.exchange
                                    wrote last edited by
                                    #17

                                    @wdormann @cR0w I need to add this to my onboarding document

                                    1 Reply Last reply
                                    1
                                    0
                                    • R relay@relay.infosec.exchange shared this topic
                                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                      Link Preview Image
                                      cve-details

                                      favicon

                                      (access.redhat.com)

                                      A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.

                                      spartan_1986@infosec.exchangeS This user is from outside of this forum
                                      spartan_1986@infosec.exchangeS This user is from outside of this forum
                                      spartan_1986@infosec.exchange
                                      wrote last edited by
                                      #18

                                      @cR0w JFC I work in IT and that paragraph still reads like something out of a James Bondage tech-bromance satire.

                                      cr0w@infosec.exchangeC 1 Reply Last reply
                                      1
                                      0
                                      • spartan_1986@infosec.exchangeS spartan_1986@infosec.exchange

                                        @cR0w JFC I work in IT and that paragraph still reads like something out of a James Bondage tech-bromance satire.

                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchange
                                        wrote last edited by
                                        #19

                                        @Spartan_1986 It's so bad.

                                        1 Reply Last reply
                                        1
                                        0
                                        Reply
                                        • Reply as topic
                                        Log in to reply
                                        • Oldest to Newest
                                        • Newest to Oldest
                                        • Most Votes


                                        • Login

                                        • Login or register to search.
                                        • First post
                                          Last post
                                        0
                                        • Categories
                                        • Recent
                                        • Tags
                                        • Popular
                                        • World
                                        • Users
                                        • Groups