Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-47190

19
FAUCET Score

IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.

First published: Jun 12, 2026Last modified: Jun 12, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.11.0, < 1.11.7CPE matchmatch criteria
cpe:2.3:a:metal3:ip-address-manager:*:*:*:*:*:*:*:*
>= 1.12.0, < 1.12.4CPE matchmatch criteria
cpe:2.3:a:metal3:ip-address-manager:*:*:*:*:*:*:*:*
1.13.0CPE matchmatch criteria
cpe:2.3:a:metal3:ip-address-manager:1.13.0:beta0:*:*:*:*:*:*
1.13.0CPE matchmatch criteria
cpe:2.3:a:metal3:ip-address-manager:1.13.0:rc0:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.7
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 46th percentile among its peer group of 687 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/metal3-io/ip-address-managerFixed in: 1.11.7
gopatch availablevia ghsa
Product: github.com/metal3-io/ip-address-managerFixed in: 1.12.4

Vendor Advisories (1)

goGHSA-49pm-43hf-6xfqmedium

IPAM controller service account granted unnecessary full access to Secrets

May 29, 2026

References

github.com / metal3-io/ip-address-manager/pull/1355
Issue TrackingPatch
github.com / metal3-io/ip-address-manager/pull/1356
Issue TrackingPatch
github.com / metal3-io/ip-address-manager/pull/1357
Issue TrackingPatch
github.com / metal3-io/ip-address-manager/security/advisories/GHSA-49pm-43hf-6xfq
MitigationVendor Advisory