Security Flaw in Multicloud Operators Subscription by Red Hat
CVE-2026-67567

9.9CRITICAL

What is CVE-2026-67567?

A flaw has been identified in the multicloud-operators-subscription component of Red Hat, which allows tenants with the ability to create HelmRelease custom resources to bypass existing security controls. The vulnerability arises due to the HelmRelease controller processing Helm chart templates using its own elevated ServiceAccount privileges without adequate validation. This oversight permits the deployment of arbitrary resources across the entire cluster, significantly compromising the security posture of the system.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787263693

Red Hat Advanced Cluster Management for Kubernetes 2.14 1787170830

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.