Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93017— Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and cluster-reader

Quick assessment

Affected
Red Hat Red Hat OpenShift Container Platform 4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述: ClusterRole 授予了该操作器的服务账号对核心 API 组中“secrets”资源的读取权限,且未设置任何命名空间(namespace)或资源名称(resourceNames)限制。这意味着该服务账号有权访问集群中所有命名空间内的所有密钥(secrets)。 参考链接: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterr

CVSS 7.7 · High

Affected Version Matrix 2

VendorProduct Version RangeStatus
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93017

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and cluster-reader
Source: CVE Program / CVE List V5
Vulnerability Description
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups: - "" resources: - secrets verbs: - get - list ``` By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace. ``` spec: serviceAccountName:"gather" ```
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-93017

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93017

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93017 (2)

Same Patch Batch · Red Hat · 2026-10-08 · 9 CVEs total

CVE-2026-89091 8.8 HIGH Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows a
CVE-2026-107466 6.1 MEDIUM Flatpak-builder: local file exfiltration via `file
CVE-2026-107651 5.5 MEDIUM Eog: eog: arbitrary code execution via heap buffer overflow in png metadata reader
CVE-2026-107445 5.4 MEDIUM Rubygem-katello: katello: katello: katello flatpak remote repositories api cross-organizat
CVE-2026-107565 5.1 MEDIUM Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow dat
CVE-2026-107604 4.9 MEDIUM Keycloak-services: keycloak-services: view-clients role allows retrieval of active client
CVE-2026-107444 4.3 MEDIUM Rubygem-katello: katello: katello: katello docker tags repositories api cross-organization
CVE-2026-107623 4.3 MEDIUM Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline

IV. Related Vulnerabilities

V. Comments for CVE-2026-93017

No comments yet


Leave a comment