


Perceptive Security
SOC/SIEM Consultancy

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A…
Published:
5 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 12:00:53
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access, Zero-Day Vulnerabilities
A critical privilege escalation vulnerability exists in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with only namespace-scoped 'edit' privileges can create a malicious Channel resource pointing to an attacker-controlled Helm repository and a Subscription resource referencing it. The app-subscription controller applies Helm chart contents using its own elevated authority without verifying the creator's subscription-admin role or restricting resources to the subscription namespace. An attacker can embed cluster-scoped resources such as ClusterRoleBindings in the Helm chart to grant their ServiceAccount the cluster-admin ClusterRole. Successful exploitation results in full cluster-admin privilege escalation across the ACM hub cluster. This behavior contradicts ACM documentation, which states non-subscription-admin users should only have resources deployed into their subscription namespace.
Technical details
Mitigation steps:
Affected products:
Red Hat Advanced Cluster Management for Kubernetes
multicluster-operators-subscription
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10090
https://access.redhat.com/security/cve/CVE-2026-10090
https://bugzilla.redhat.com/show_bug.cgi?id=2483292
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
