Description
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
Published: 2026-08-12
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) allows a tenant with namespace‑administration rights to perform a confused‑deputy attack. By creating Subscription Custom Resources that reference a highly privileged ServiceAccount, the tenant can deploy resources that have cluster‑wide scope, effectively bypassing normal access controls and gaining the ability to run arbitrary code throughout the cluster.

Affected Systems

The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes version 2. Specifically, the multicloud-operators-subscription component is impacted; users should verify that their deployments use this component and assess the permissions granted to the application‑manager ServiceAccount.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity, and the EPSS score is not available, so exact exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by creating Subscription resources from within a namespace they administrate, provided they have permission to instantiate custom resources. Successful exploitation results in privilege escalation and potentially arbitrary code execution at cluster level. The lack of an official patch underscores the importance of mitigating the problem through RBAC restrictions.

Generated by OpenCVE AI on August 12, 2026 at 22:52 UTC.

Remediation

Vendor Workaround

To mitigate this issue, Red Hat Advanced Cluster Management for Kubernetes administrators should configure the application-manager addon to use the least-privilege RBAC variant. This involves applying the addon/manifests/permission/role.yaml configuration, which restricts the permissions granted to the application-manager ServiceAccount. Consult Red Hat documentation for specific instructions on how to apply custom RBAC configurations for RHACM addons. Applying this change may require a restart or reload of the affected components to take effect.


OpenCVE Recommended Actions

  • Configure the application‑manager addon to use the least‑privilege RBAC variant by applying the role.yaml configuration from addon/manifests/permission, which limits permissions granted to the application‑manager ServiceAccount
  • Restart or reload the affected components to ensure the new RBAC settings take effect
  • If a patch is later released, upgrade RHACM to the latest version that contains the fix

Generated by OpenCVE AI on August 12, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
Title Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)
First Time appeared Redhat
Redhat acm
Weaknesses CWE-250
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-12T19:41:18.859Z

Reserved: 2026-08-11T17:40:07.962Z

Link: CVE-2026-72508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:49.650

Modified: 2026-08-12T20:17:49.650

Link: CVE-2026-72508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:00:05Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges