open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker

cve CVE-2026-91182 1 source, 1 claim · Watch

Red Hat writes:
open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker the claim

What each source says

PropertySourceSaidMeans here
Cvss
cvss
Red Hat3.3
receipt
Source
Red Hat
Its words
3.3
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 00:12 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-91182",
  "CWE": "CWE-639",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2533540",
  "bugzilla_description": "open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker",
  "cvss3_score": "3.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-23T14:43:14Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-91182.json",
  "severity": "low"
}
—
Cwe
cwe
Red HatCWE-639
receipt
Source
Red Hat
Its words
CWE-639
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 00:12 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-91182",
  "CWE": "CWE-639",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2533540",
  "bugzilla_description": "open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker",
  "cvss3_score": "3.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-23T14:43:14Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-91182.json",
  "severity": "low"
}
—
Severity
severity
Red Hatlow
A flaw that is unlikely to be exploited, or whose impact is minimal.
receipt
Source
Red Hat
Its words
low
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 00:12 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-91182",
  "CWE": "CWE-639",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2533540",
  "bugzilla_description": "open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker",
  "cvss3_score": "3.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-23T14:43:14Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-91182.json",
  "severity": "low"
}
—

vulnerability

open-cluster-management: Open-Cluster-Management: Privilege escalation and unauthorized resource modification in gRPC broker
zetlyn/cve-redhat · 2026-09-23
cvss 3.3 cwe CWE-639 severity low source