Privilege Escalation Vulnerability in Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-10090

9.9CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
5 August 2026

What is CVE-2026-10090?

A security flaw exists in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes. Users with 'edit' privileges can create Channel and Subscription resources pointing to controlled Helm repositories, enabling the app-subscription controller to fetch Helm chart contents with elevated permissions. This process lacks verification of the subscription creator's roles and allows unauthorized access to cluster-scoped resources, which could lead to significant privilege escalation, contradicting the intended resource limitations set forth in official ACM documentation.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
.