—
GO-2026-5564
Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation in open-cluster-management.io/ocm
Quick fix
GO-2026-5564 — open-cluster-management.io/ocm: upgrade to the fixed version with the command below.
go get open-cluster-management.io/ocm@v1.2.1Details
Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation in open-cluster-management.io/ocm
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/open-cluster-management.io/ocm
Introduced in:
0Fixed in: 1.2.1Fix
go get open-cluster-management.io/ocm@v1.2.1References
- https://github.com/advisories/GHSA-q4gv-pjmh-c735[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-4740[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2026-4740[WEB]
- https://blog.arfevrier.fr/open-cluster-management-cross-cluster-escape[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2450590[WEB]
- https://github.com/open-cluster-management-io/ocm/commit/9e70cc1e21a15239c81111062c0b37df4b5a8026[WEB]