Description
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
Published: 2026-08-17
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the multicloud-operators-subscription component allows a user who can create a Subscription on a managed cluster to inject crafted annotations. These annotations are trusted by the controller's Service Account due to the isclusteradmin() function, enabling the attacker to deploy arbitrary resources into any namespace with the controller's elevated permissions. The vulnerability can result in unauthorized access to cluster resources and full control over the managed environment.

Affected Systems

Affected systems include Red Hat Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, and Red Hat OpenShift Data Foundation 4. Version information is not provided in the advisory.

Risk and Exploitability

The CVSS score of 9.9 places this flaw in the critical range, indicating high impact on confidentiality, integrity, and availability. The EPSS score is not available, but the vulnerability’s nature suggests that an attacker already possessing a user role with rights to create Subscription objects can exploit it with minimal effort. Commercial exploitation is unlikely to be discovered yet because the issue is not listed in the CISA KEV catalog, yet the ease of deployment via normal cluster management tools makes it a high priority for patching. Inferred attack vector is local within the cluster, where a privileged user crafts a Subscription with malicious annotations to trigger the privileged controller.

Generated by OpenCVE AI on August 17, 2026 at 19:30 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Update or upgrade the multicloud-operators-subscription component to a version that includes the vendor fix for this privilege‑escalation flaw.
  • Restrict Sub‑scription creation to cluster administrators by tightening RBAC policies or using Kubernetes RoleBinding scopes.
  • Implement an admission webhook or OPA gate that validates Subscription annotations and rejects any that do not meet a strict whitelist or syntax policy.

Generated by OpenCVE AI on August 17, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
Title Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters
First Time appeared Redhat
Redhat acm
Redhat multicluster Globalhub
Redhat openshift
Redhat openshift Data Foundation
Weaknesses CWE-863
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:multicluster_globalhub
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_data_foundation:4
Vendors & Products Redhat
Redhat acm
Redhat multicluster Globalhub
Redhat openshift
Redhat openshift Data Foundation
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Acm Multicluster Globalhub Openshift Openshift Data Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-17T18:12:36.136Z

Reserved: 2026-07-27T17:51:24.886Z

Link: CVE-2026-66792

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:34.237

Modified: 2026-08-17T19:16:34.237

Link: CVE-2026-66792

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T17:25:00Z

Links: CVE-2026-66792 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T19:30:17Z

Weaknesses