CVE-2026-10079 PUBLISHED

Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection

Assigner: redhat
Reserved: 29.05.2026 Published: 31.07.2026 Updated: 31.07.2026

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
CVSS Score: 8.5

Product Status

Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected

Workarounds

There is no complete mitigation other than installing the update once available.

Credits

  • This issue was discovered by Moritz Clasmeier (Red Hat).

References

Problem Types

  • Insufficient Verification of Data Authenticity CWE