Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10090— Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription

Quick assessment

Affected
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Red Hat Advanced Cluster Management for Kubernetes是美国Red Hat公司的一个Kubernetes多集群管理平台。 Red Hat Advanced Cluster Management for Kubernetes 2版本存在权限许可和访问控制问题漏洞,该漏洞源于Application Subscription控制器未验证订阅创建者是否具有“open-cluster-management:subscription-admin”角色且未限制应用资源到订阅

CVSS 9.0 · Critical EPSS 0.58% · P45
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10090

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the "open-cluster-management:subscription-admin" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the "cluster-admin" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
特权定义了不安全动作
Source: CVE Program / CVE List V5
Vulnerability Title
Red Hat Advanced Cluster Management for Kubernetes 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat Advanced Cluster Management for Kubernetes是美国Red Hat公司的一个Kubernetes多集群管理平台。 Red Hat Advanced Cluster Management for Kubernetes 2版本存在权限许可和访问控制问题漏洞,该漏洞源于Application Subscription控制器未验证订阅创建者是否具有“open-cluster-management:subscription-admin”角色且未限制应用资源到订阅
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584 ~ * cpe:/a:redhat:acm:2.11::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13 1787263693 ~ * cpe:/a:redhat:acm:2.13::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14 1787170830 ~ * cpe:/a:redhat:acm:2.14::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15 1787240030 ~ * cpe:/a:redhat:acm:2.15::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16 1787242321 ~ * cpe:/a:redhat:acm:2.16::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17 1787242108 ~ * cpe:/a:redhat:acm:2.17::el9

II. Public POCs for CVE-2026-10090

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10090

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-10090 (8)

Same Patch Batch · Red Hat · 2026-08-05 · 11 CVEs total

CVE-2026-10059 9.1 CRITICAL Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl
CVE-2026-15572 8.8 HIGH Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows p
CVE-2026-15573 8.1 HIGH Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i
CVE-2026-16102 8.1 HIGH Keycloak-services: keycloak-services: default dcr policy allows role forgery via user prop
CVE-2026-16443 7.4 HIGH Keycloak-services: keycloak-services: saml broker metadata import disables response signat
CVE-2026-16442 7.4 HIGH Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r
CVE-2026-16100 6.5 MEDIUM Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v
CVE-2026-49331 6.5 MEDIUM Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on
CVE-2026-44605 5.5 MEDIUM Rpm: heap buffer overflow in ndb slot table parsing
CVE-2026-16071 5.4 MEDIUM Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users

IV. Related Vulnerabilities

V. Comments for CVE-2026-10090

No comments yet


Leave a comment