Impact
A vulnerability in the multicloud‑operators‑subscription component allows a tenant who can create HelmRelease custom resources to bypass existing security controls. The HelmRelease controller processes chart templates using its own elevated ServiceAccount privileges without proper validation, giving the tenant the ability to deploy arbitrary resources throughout the cluster. The consequences are an unrestricted ability to modify cluster‑wide configuration, which can lead to complete compromise of confidentiality, integrity, and availability.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes 2 is affected by this flaw. Tenants who can create HelmRelease resources in this environment risk exploiting the issue; any user or service account with such capability is a potential attacker.
Risk and Exploitability
The flaw is scored CVSS 9.9, indicating critical severity. An attacker can gain cluster‑wide deployment power without needing additional credentials. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of validation and the high score suggest that exploitation is feasible and could have grave impact if left unmitigated. The likely attack vector is through the creation of a malicious HelmRelease object by an authenticated, yet untrusted tenant.
OpenCVE Enrichment