Impact
The vulnerability resides in the CSR auto‑approval logic of the ManagedCluster‑Import‑Controller for Red Hat Multicluster Engine and represents a CWE-295: Improper Certificate Validation. The controller fails to validate the signer name and does not decode the PEM‑encoded X.509 CSR, allowing a privileged service account on a spoke cluster to submit a crafted CSR. A successfully auto‑approved malicious CSR elevates the attacker’s privileges to the hub cluster, granting administrative access. This results in a full compromise of the hub with potential disclosure, modification, and availability impacts.
Affected Systems
All deployments of Red Hat Multicluster Engine for Kubernetes that include the managedcluster‑import‑controller and are running versions 2.6, 2.8, 2.9, 2.10, 2.11, or 2.17 are affected. Until a patch is released, these specific versions should be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a high‑risk condition. EPSS is <1%, indicating a very low exploitation probability, and the flaw is not yet listed in the CISA KEV catalog, but the combination of a privileged service account on a spoke cluster and the lack of validation creates a realistic attack vector. Once accepted, the rogue CSR confers hub‑level administrative credentials, enabling complete control over the cluster. The attack requires no additional network access beyond the existing privileged spoke account, so the attack surface is relatively small yet devastating.
OpenCVE Enrichment