RHSA-2026:18584HighCVSS 7.5

Red Hat Security Advisory: Assisted Installer RHEL 8 components for Multicluster Engine for Kubernetes 2.9.4

Published
May 19, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-7163 — assisted-service: assisted-service: Authenticated users can gain administrative access to OpenShift clusters via credential disclosure CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

🎯 Affected products5

  • multicluster engine for Kubernetes 2.9
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:1a5ec032ec4d4833e2cd038ee1063479583d0c22d9e080b5394d2135ce35369f_ppc64le as a component of multicluster engine for Kubernetes 2.9
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:9f73c8b0303fb8f6e392bbe25815c019dbc69c69f193bb6257bd6c1116f1cf50_s390x as a component of multicluster engine for Kubernetes 2.9
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:fc440baf4dbd00fc403741f3724ee36e5da716e41b775ac0ed4f8048971d10a6_amd64 as a component of multicluster engine for Kubernetes 2.9
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:fec24ce70e2d31f2f21761cdef6cdc3ea6a62e98951c73a7a3eb6ef6720da01b_arm64 as a component of multicluster engine for Kubernetes 2.9

✅ Remediation

For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.14. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)