Impact
A flaw in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) allows a tenant with namespace‑administration rights to perform a confused‑deputy attack. By creating Subscription Custom Resources that reference a highly privileged ServiceAccount, the tenant can deploy resources that have cluster‑wide scope, effectively bypassing normal access controls and gaining the ability to run arbitrary code throughout the cluster.
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes version 2. Specifically, the multicloud-operators-subscription component is impacted; users should verify that their deployments use this component and assess the permissions granted to the application‑manager ServiceAccount.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, and the EPSS score is not available, so exact exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by creating Subscription resources from within a namespace they administrate, provided they have permission to instantiate custom resources. Successful exploitation results in privilege escalation and potentially arbitrary code execution at cluster level. The lack of an official patch underscores the importance of mitigating the problem through RBAC restrictions.
OpenCVE Enrichment