Security Flaw in Multicloud Operators Subscription by Red Hat
CVE-2026-67567
9.9CRITICAL
Key Information:
What is CVE-2026-67567?
A flaw has been identified in the multicloud-operators-subscription component of Red Hat, which allows tenants with the ability to create HelmRelease custom resources to bypass existing security controls. The vulnerability arises due to the HelmRelease controller processing Helm chart templates using its own elevated ServiceAccount privileges without adequate validation. This oversight permits the deployment of arbitrary resources across the entire cluster, significantly compromising the security posture of the system.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584
Red Hat Advanced Cluster Management for Kubernetes 2.13 1787263693
Red Hat Advanced Cluster Management for Kubernetes 2.14 1787170830