Impact
A vulnerability in Lighthouse allows a remote attacker who has gained control of a spoke cluster to manipulate a label or annotation on the broker object so that the namespace chosen for injected resources is derived from attacker‑controlled data. This bypasses normal authorization controls and permits the attacker to insert EndpointSlices and ServiceImports into any namespace, including critical system namespaces such as kube‑system and openshift‑*. The consequence is that the attacker can achieve privilege escalation or further system compromise on peer clusters.
Affected Systems
The flaw affects Red Hat Advanced Cluster Management for Kubernetes 2 when it is deployed with Lighthouse integration. No specific product version is listed, so the vulnerability applies to all editions of AC M 2 that have Lighthouse enabled.
Risk and Exploitability
The CVSS score is 3.7, indicating low severity. The EPSS score is < 1 %, and the flaw is not listed in CISA KEV, suggesting a low likelihood of exploitation. Based on the description, it is inferred that the attacker must first compromise a spoke cluster; this prerequisite is a realistic threat scenario. Once the attacker injects resources, they can achieve elevated privileges or system compromise. No official workaround is available, so monitoring for unauthorized resource creation and restricting broker object labels are recommended as mitigations.
OpenCVE Enrichment