Impact
A flaw was found in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace‑scoped edit privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription that references it. The controller then fetches and applies the chart contents with its own elevated authority, without checking whether the subscription creator has the open‑cluster‑management:subscription‑admin role and without restricting applied resources to the subscription namespace. This omission allows an attacker to include cluster‑scoped objects in the Helm chart, such as a ClusterRoleBinding that grants the attacker’s ServiceAccount the cluster‑admin ClusterRole. Successful exploitation results in full cluster‑admin privilege escalation. The CVSS score is 9 and the weakness corresponds to CWE‑267.
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes version 2 (ACM 2). Exact sub‑version details are not publicly disclosed, but any installation of ACM 2 that still uses the default multicluster‑operators‑subscription controller is impacted.
Risk and Exploitability
With a CVSS score of 9 the flaw is rated critical. The EPSS score is < 1%, indicating a low probability of exploitation, yet the risk remains high due to the lack of a patch and the requirement of only namespace‑scoped edit rights. Attackers can deploy cluster‑scoped resources through a controlled Helm repository, gaining cluster‑admin rights and potentially compromising the entire cluster. This vulnerability is not listed in the CISA KEV catalog. Without an official fix, this risk remains high for all affected ACM 2 deployments.
OpenCVE Enrichment