ServiceAccount Privilege Escalation in Insights Client by Red Hat
CVE-2026-71846
6.5MEDIUM
What is CVE-2026-71846?
A security flaw in the insights-client allows the ServiceAccount to be bound to a ClusterRole with excessive permissions, enabling unauthorized access to sensitive information. Specifically, the ServiceAccount holds permissions to get, list, and watch all secrets across the cluster, whereas access should be limited to a specific secret. This can lead to a potential compromise where attackers could gain read access to critical credentials, including kubeconfigs for managed clusters.