RBAC Role Vulnerability in OpenShift Cluster Samples Operator
CVE-2026-107176
6.8MEDIUM
What is CVE-2026-107176?
A security issue has been identified in the cluster-samples-operator used in OpenShift. The role 'coreos-pull-secret-reader' in the 'openshift-config' namespace permits excessive permissions, allowing access to all Secret resources without proper scoping by resourceNames. This exposes an unnecessary risk, as the operator should only access the 'pull-secret' Secret. If an attacker gains access to the samples-operator pod or its service account token, they could potentially read all secrets stored in openshift-config, including critical OAuth identity provider credentials, cloud provider credentials, and other sensitive configurations of the cluster.