top of page
perceptive_background_267k.jpg

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 10:00:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access, Zero-Day Vulnerabilities

A critical privilege escalation vulnerability exists in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with only namespace-scoped 'edit' privileges can create a malicious Channel resource pointing to an attacker-controlled Helm repository and a Subscription resource referencing it. The app-subscription controller applies Helm chart contents using its own elevated authority without verifying the creator's subscription-admin role or restricting resources to the subscription namespace. An attacker can embed cluster-scoped resources such as ClusterRoleBindings in the Helm chart to grant their ServiceAccount the cluster-admin ClusterRole. Successful exploitation results in full cluster-admin privilege escalation across the ACM hub cluster. This behavior contradicts ACM documentation, which states non-subscription-admin users should only have resources deployed into their subscription namespace.

Technical details

Mitigation steps:

Affected products:

Red Hat Advanced Cluster Management for Kubernetes
multicluster-operators-subscription

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page