Excessive RBAC Permissions in Red Hat OpenShift insights-operator
A misconfiguration in the OpenShift insights-operator ClusterRole grants the 'gather' service account cluster-wide read access to secrets, enabling privilege escalation for attackers who can spawn pods with that identity.
CVE search metadata
CVE search record: CVE-2026-93017. Severity: high. CVSS: 7.7. KEV: no. Product: OpenShift Container Platform. Brief: Excessive RBAC Permissions in Red Hat OpenShift insights-operator. Brief link: https://feed.craftedsignal.io/briefs/2026-10-openshift-insights-rbac/
Red Hat OpenShift Container Platform is impacted by a critical privilege escalation vulnerability (CVE-2026-93017) stemming from an overly permissive ClusterRole assigned to the insights-operator. The insights-operator-gather ClusterRole incorrectly grants the gather service account get and list permissions for secrets in the core API group, without limiting the scope to specific namespaces or resources. This effectively permits the service account to access every secret across the entire cluster.
An attacker who has gained the ability to create pods or influence pod specifications - for instance, through a compromised developer account or an application-layer injection vulnerability - can mount the gather service account to an attacker-controlled pod. Once the pod is running with this identity, the attacker can use standard Kubernetes API calls to retrieve secrets, such as API keys, database credentials, or TLS certificates, leading to a complete compromise of sensitive information stored within the cluster.
Attack Chain
- Attacker identifies a vulnerability (e.g., remote code execution or unauthorized access) allowing pod creation or modification within the cluster.
- Attacker crafts a malicious pod specification that mounts the
gatherservice account usingserviceAccountName: "gather". - Attacker deploys the malicious pod into the cluster via the API server.
- The pod executes, gaining the elevated permissions associated with the
gatherservice account. - Attacker executes
kubectl get secrets --all-namespacesor makes equivalent API requests from within the pod. - The Kubernetes API server grants the request due to the over-privileged ClusterRole.
- Attacker exfiltrates gathered secrets to external infrastructure to achieve final objectives.
Impact
Successful exploitation results in full exposure of cluster-wide secrets, including but not limited to database credentials, service-to-service authentication tokens, and TLS private keys. This can facilitate lateral movement within the cluster, escalation to other services, and access to external resources secured by the compromised credentials.
Recommendation
- Review the current cluster-wide RBAC policies for the
insights-operatorand restrict the scope of theinsights-operator-gatherrole to only those namespaces and resources strictly necessary for its telemetry-gathering function. - Implement Kubernetes Admission Controllers or Policy-as-Code (such as OPA Gatekeeper or Kyverno) to prevent the arbitrary mounting of sensitive service accounts by user-defined pods.
- Audit existing pods and service account bindings to identify unauthorized use of the
gatherservice account. - Monitor cluster API audit logs for suspicious
getorlistrequests onsecretsresources originating from thegatherservice account.
Immediate actions
Review and restrict RBAC for the insights-operator-gather ClusterRole.
Threat Hunt
Identify pods using serviceAccountName: gather
Data: Kubernetes Audit Logs or cluster resource manifests
Mitigations
Patch OpenShift Container Platform according to Red Hat guidance.
CVE-2026-93017