CVE-2026-47190Metal3 · Ip-address-manager
Vulnerability data via NVD (ingested)
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the controller pod were compromised (e.g. via supply chain attack or container escape), an attacker could leverage these excessive permissions to read, modify, or delete Secrets in the namespace, potentially exposing credentials and other sensitive data. This issue has been patched in versions 1.11.7, 1.12.4, and 1.13.0.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-47190product:"Metal3 Ip-address-manager"http.html:"Ip-address-manager"More intel sources (5)
vuln:CVE-2026-47190vulnerabilities.cve_id: CVE-2026-47190CVE-2026-47190CVE-2026-47190"CVE-2026-47190" exploit -site:nvd.nist.gov