CVE-2026-23990 | controlplaneio-fluxcd flux-operator up to 0.39.x empty privileges management (GHSA-4xh5-jcj2-ch8q)
A vulnerability labeled as critical has been found in controlplaneio-fluxcd flux-operator up to 0.39.x. Impacted is an unknown function. Executing a manipulation of the argument empty can lead to improper privilege management.
This vulnerability is handled as CVE-2026-23990. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.