Impact
A privilege escalation flaw in multicloud-operators-subscription allows a namespace administrator to manipulate Channel.Spec.SecretRef.Namespace so that the controller copies the contents of a secret from any namespace into the attacker’s namespace, exposing sensitive data. Since the flaw is driven by the legitimate Channel resource API, it is a classic example of using an existing privilege to read restricted data (CWE-639). The impact is the unauthorized disclosure of secrets such as passwords or tokens.
Affected Systems
The affected product is Red Hat Advanced Cluster Management for Kubernetes 2, specifically any deployment that utilizes the multicloud-operators-subscription component. All users who can create Channel and Subscription resources within a namespace are subject to the vulnerability; no specific component version is listed, so all ACM 2 releases that have not yet applied the vendor fix are potentially impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, but the EPSS score of less than 1% implies a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so there are currently no known widespread exploitation campaigns. The likely attack vector requires privileged cluster access to create resources; an attacker could therefore achieve cross-namespace secret disclosure from within the cluster.
OpenCVE Enrichment