CVE-2026-47190
4.4 MEDIUMIPAM is the IP address Manager for Cluster API Provider Metal3
Published: 2026-06-12 · Last updated: 2026-06-12
Severity and scoring
- CVSS
- 4.4 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-250
Description
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-47190
- [Other]https://github.com/metal3-io/ip-address-manager/pull/1355
- [Other]https://github.com/metal3-io/ip-address-manager/pull/1356
- [Other]https://github.com/metal3-io/ip-address-manager/pull/1357
- [Other]https://github.com/metal3-io/ip-address-manager/security/advisories/GHSA-49pm-43hf-6xfq
Related CVEs
Same CWE
- CVE-2026-12027 — Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the rende... (9.6 CRITICAL)
- CVE-2026-11626 — CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, which is a type of...
- CVE-2026-50566 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)
- CVE-2026-50565 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (4.9 MEDIUM)
- CVE-2026-46618 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes