By vendor
Metal3 vulnerabilities
Known CVEs affecting Metal3 products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-47190MEDIUM 4.4
IPAM (IP Address Manager) for Cluster API Provider Metal3 granted its controller pod excessive permissions to read, modify, and delete Kubernetes Secrets—a capability it never uses during normal operation. If an attacker compromised the controller pod through a supply chain attack or container escape, they could exploit these overly broad permissions to steal sensitive credentials and other secret data stored in the cluster. This permission misconfiguration has been corrected in patched versions.