AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-50237

HIGH · CVSS 7.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the OpenShift Console Helm catalog proxy, allowing a namespace tenant to inject a ProjectHelmChartRepository with an arbitrary URL, which the console pod fetches server-side, circumventing egress restrictions. This flaw, combined with catalog metadata manipulation and admin-mediated chart installations, can lead to privilege escalation within the system. Organizations using OpenShift should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-50237
Severity
HIGH
CVSS
7.4
EPSS
0.17%

Original NVD Description

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.