VDB

ESB-2026.5184

ESB-2026.5184 PUBLISHED CVSS 7.5 HIGH

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.5184 zero trust workload identity manager for Red Hat OpenShift 1.0.1 15 May 2026 =========================================================================== AUSCERT Security Bulletin Summary --------------------------------- Product: Red Hat OpenShift 1.0.1 Publisher: Red Hat Operating System: Red Hat Resolution: Patch/Upgrade CVE Names: CVE-2026-21441 Original Bulletin: https://access.redhat.com/errata/RHSA-2026:17456 Comment: CVSS (Max): 7.5 CVE-2026-21441 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) CVSS Source: Red Hat Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H EPSS (Max): 0.0% (9th) CVE-2026-21441 2026-05-13 - --------------------------BEGIN INCLUDED TEXT-------------------- RHSA-2026:17456 - Security Advisory Issued: 2026-05-14 Updated: 2026-05-14 Synopsis Trust workload identity manager for red hat openshift 1.0.1 Type/Severity Security Advisory: Important Topic zero trust workload identity manager for Red Hat OpenShift 1.0.1 Description The Zero Trust Workload Identity Manager (ZTWIM) is a day-2 operator. The operator manages lifecycle of operand components from SPIRE project. The goal of ZTWIM is to provide secure, verifiable workload identities for workloads in multi-cloud environments. The operand components automate identity issuance, rotation, and verification, enhancing the zero-trust security model while eliminating static credentials. The current release of zero trust workload identity manager for Red Hat OpenShift is for Technology Preview. Solution Before installing the operator, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images will differ depending on the installation plan approval policy that will be used while installing thezero trust workload identity manager for Red Hat OpenShift. o If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. o If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. Fixes (none) CVEs o CVE-2026-21441 References o https://access.redhat.com/security/updates/classification/ o https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/ html/security_and_compliance/zero-trust-workload-identity-manager - --------------------------END INCLUDED TEXT---------------------- You have received this e-mail bulletin as a result of your organisation's registration with AUSCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AUSCERT's members. As AUSCERT did not write the document quoted above, AUSCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AUSCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://portal.auscert.org.au/bulletins/ =========================================================================== AUSCERT The University of Queensland, Brisbane QLD 4072 Australia e: auscert@auscert.org.au t: +61 (0)7 3365 4417 Allies in Cyber Security ===========================================================================

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift 1.0.1

Timeline

  • May 14, 2026 CVE Published
  • May 15, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›