Bug 2483158 (CVE-2026-10079) - CVE-2026-10079 stackrox: stackrox: Deploy-time policy enforcement and visibility bypass via label injection
Summary: CVE-2026-10079 stackrox: stackrox: Deploy-time policy enforcement and visibil...
Keywords:
Status: NEW
Alias: CVE-2026-10079
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-29 07:40 UTC by OSIDB Bzimport
Modified: 2026-07-31 09:01 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-29 07:40:28 UTC
A flaw was found in RHACS. When converting Kubernetes Deployments, ACS reads the label openshift.io/encoded-deployment-config and JSON-unmarshals its value to replace deployment identity metadata. A user with permission to create Deployments can set this label to "null", which is valid under Kubernetes label rules but produces empty metadata (no UID, name, or labels; namespace falls back to "default"). Deploy-time policy violations then disappear from the UI, the deployment is not persisted in Central and affected workloads collide in the Sensor store. Container specs are still read from the real object, but ACS loses the identity needed for enforcement and reporting.


Note You need to log in before you can comment on or make changes to this bug.