AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-9165

HIGH · CVSS 7.7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

A vulnerability in Red Hat Advanced Cluster Security for Kubernetes allows authenticated users to exploit the GraphQL API by sending deeply nested queries, leading to excessive resource consumption and potential denial of service for the management plane. Organizations utilizing RHACS should prioritize addressing this issue to protect their Kubernetes environments from service disruptions. Immediate action is recommended for teams managing sensitive workloads or relying heavily on the affected API.

CVE
CVE-2026-9165
Severity
HIGH
CVSS
7.7
EPSS
0.31%
Kubernetes

Original NVD Description

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.