Description
A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources.
Published: n/a
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a namespace administrator with privileges in the open-cluster-management-backup namespace to trigger an unrestricted, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive‑labelled Secrets and ConfigMaps by setting the cleanupBeforeRestore field to CleanupAll in the Restore Custom Resource. The unguarded mass‑delete leads to a denial of service on the entire hub cluster by removing critical resources.

Affected Systems

The affected system is the cluster-backup-operator component running in Red Hat Advanced Cluster Management (ACM) clusters. Any instance where a namespace administrator controls the open-cluster-management-backup namespace and the Operator ServiceAccount has permissions to delete Secrets and ConfigMaps is impacted. Specific product details are limited to the cluster-backup-operator within ACM environments.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability. EPSS is not available, so the exploitation probability is not quantified, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widely used exploits yet. The attack requires namespace administrative rights and a ServiceAccount with delete privileges; once the cleanupBeforeRestore field is set to CleanupAll, the operator performs mass deletion without further checks, resulting in a wide‑area denial of service. This direct action within the cluster makes the risk significant for clusters with permissive role configurations.

Generated by OpenCVE AI on August 12, 2026 at 15:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade for cluster-backup-operator that restricts the cleanupBeforeRestore action.
  • Restrict the cleanupBeforeRestore feature to disallow the CleanupAll value or require additional authorization before executing mass deletion.
  • Limit the Operator ServiceAccount’s permissions to only those needed for backup operations, removing general delete rights on Secrets and ConfigMaps.

Generated by OpenCVE AI on August 12, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources.
Title cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount
Weaknesses CWE-862
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Important


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T00:00:00Z

Links: CVE-2026-66800 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:00:04Z

Weaknesses