Privilege Escalation Vulnerability in Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-10090
9.9CRITICAL
What is CVE-2026-10090?
A security flaw exists in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes. Users with 'edit' privileges can create Channel and Subscription resources pointing to controlled Helm repositories, enabling the app-subscription controller to fetch Helm chart contents with elevated permissions. This process lacks verification of the subscription creator's roles and allows unauthorized access to cluster-scoped resources, which could lead to significant privilege escalation, contradicting the intended resource limitations set forth in official ACM documentation.
References
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.