Impact
A flaw in Red Hat Advanced Cluster Management for Kubernetes 2’s multicloud-operators-channel component allows an agent belonging to a compromised managed cluster to obtain read permissions for all Secrets and ConfigMaps in every Channel namespace on the hub. This excessive role grants the ability to expose credentials for other tenants’ Git and Helm repositories, leading to significant information disclosure.
Affected Systems
The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes 2, specifically the multicloud-operators-channel component. No additional product patch levels are listed in the CVE data; any version of the component that lacks the fix is vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity risk. The EPSS score of less than 1% suggests that real-world exploitation is rare but not impossible. The vulnerability is not listed in CISA KEV. The likely attack path is a compromised cluster agent exercising its granted permissions, potentially after lateral movement into the hub environment. Once in place, the agent can read sensitive configuration data, compromising tenant confidentiality. The weakness is classified as CWE‑269, indicating an improper elevation of privilege through over‑permissive role assignments.
OpenCVE Enrichment