Impact
The flaw in the insights-client causes its ServiceAccount to be bound to a ClusterRole that grants cluster‑wide permissions to list, get, and watch all Secrets, while the client only needs access to one specific Secret. If the insights‑client pod or its token is compromised, an attacker gains read access to every Secret in the hub cluster, including kubeconfig files for managed clusters and other sensitive credentials. This creates a high‑impact security risk by leaking confidential information and potentially enabling further attacks. The weakness is a classic privilege misuse (CWE‑250).
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes 2 is affected. The vulnerability resides in the insights‑client component of this product. No other vendors or product versions are listed. Specific versions are not provided in the CNA data, so all current deployments of ACM 2 should be considered susceptible unless patched.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is unavailable, so the current likelihood of exploitation is not quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers need to compromise the pod or steal the ServiceAccount token; once they have that, they can read all Secrets cluster‑wide. Failure to restrict the role grants an attacker a breadth of exploitable secrets that could facilitate further lateral movement or data exfiltration.
OpenCVE Enrichment