Impact
The flaw resides in the search-v2-operator’s ClusterRole, which grants it permissions equivalent to a cluster administrator, including impersonation of other users, writing RBAC configurations, approving certificate signing requests, and managing ManifestWork resources. This over-privilege enables an attacker who can manipulate the operator to elevate their capabilities within the cluster, potentially allowing full control over cluster configuration, secrets, and node resources.
Affected Systems
Affected systems include Red Hat Advanced Cluster Management for Kubernetes 2. All instances running this operator are potentially vulnerable, regardless of minor version differences, because the flaw is tied to the operator’s default role configuration.
Risk and Exploitability
The CVSS score of 9.9 indicates that the vulnerability can have a catastrophic impact if exploited. The EPSS score is not available, but the lack of an official workaround and the absence of a CISA KEV listing do not reduce the risk. An attacker with access to a compromised pod or service account trusted by the operator could exploit the privileged role to gain cluster-admin rights, leading to data exfiltration, denial of service, or further lateral movement.
OpenCVE Enrichment