{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/advanced-cluster-management-for-kubernetes/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-10090"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Advanced Cluster Management for Kubernetes"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","kubernetes","cve"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-10090 describes a critical security vulnerability within the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management (ACM) for Kubernetes. The flaw stems from a lack of proper authorization checks during the processing of Helm charts. Specifically, the controller fails to verify if a user has the required 'open-cluster-management:subscription-admin' role before executing Helm charts provided by the user.\u003c/p\u003e\n\u003cp\u003eFurthermore, the controller applies these resources with elevated internal service account privileges and fails to restrict the scope of the deployed resources to the subscription namespace. An attacker with standard namespace-scoped 'edit' permissions can craft a malicious Helm chart containing cluster-scoped resources, such as ClusterRoleBindings. When the controller processes the subscription, it installs these resources cluster-wide, enabling the attacker to grant their own ServiceAccount elevated 'cluster-admin' privileges. This bypasses the security boundaries established by the ACM architecture.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full cluster-admin privilege escalation on the affected Kubernetes cluster. This allows an unauthorized user to gain control over the entire cluster, potentially leading to unauthorized access to sensitive data, modification of cluster resources, and disruption of services across all namespaces. This vulnerability affects all versions of Red Hat Advanced Cluster Management where the multicluster-operators-subscription controller is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit existing Subscription and Channel resources for unauthorized Helm repository sources or suspicious cluster-scoped resource definitions.\u003c/li\u003e\n\u003cli\u003eImplement strict RBAC policies that limit the ability of users to create Subscription and Channel resources within ACM hub namespaces.\u003c/li\u003e\n\u003cli\u003eApply the latest security updates provided by Red Hat to patch the multicluster-operators-subscription controller for CVE-2026-10090.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes API audit logs for 'create' or 'update' operations on Subscription and Channel resources originating from non-admin accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T11:15:31Z","date_published":"2026-08-05T11:15:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-10090/","summary":"An insecure configuration in the Red Hat Advanced Cluster Management Application Subscription controller allows users with namespace-scoped edit privileges to escalate to cluster-admin by deploying unauthorized cluster-scoped resources via Helm charts.","title":"Privilege Escalation in Red Hat Advanced Cluster Management","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-10090/"}],"language":"en","title":"CraftedSignal Threat Feed - Advanced Cluster Management for Kubernetes","version":"https://jsonfeed.org/version/1.1"}