Impact
This vulnerability allows a namespace administrator with privileges in the open-cluster-management-backup namespace to trigger an unrestricted, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive‑labelled Secrets and ConfigMaps by setting the cleanupBeforeRestore field to CleanupAll in the Restore Custom Resource. The unguarded mass‑delete leads to a denial of service on the entire hub cluster by removing critical resources.
Affected Systems
The affected system is the cluster-backup-operator component running in Red Hat Advanced Cluster Management (ACM) clusters. Any instance where a namespace administrator controls the open-cluster-management-backup namespace and the Operator ServiceAccount has permissions to delete Secrets and ConfigMaps is impacted. Specific product details are limited to the cluster-backup-operator within ACM environments.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. EPSS is not available, so the exploitation probability is not quantified, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widely used exploits yet. The attack requires namespace administrative rights and a ServiceAccount with delete privileges; once the cleanupBeforeRestore field is set to CleanupAll, the operator performs mass deletion without further checks, resulting in a wide‑area denial of service. This direct action within the cluster makes the risk significant for clusters with permissive role configurations.
OpenCVE Enrichment