<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Multicloud-Operators-Subscription - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/multicloud-operators-subscription/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 03:54:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/multicloud-operators-subscription/feed.xml" rel="self" type="application/rss+xml"/><item><title>Information Disclosure in multicloud-operators-subscription via Improper Cross-Namespace Secret Reference</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2026-66878/</link><pubDate>Wed, 12 Aug 2026 03:54:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2026-66878/</guid><description>A vulnerability in the multicloud-operators-subscription controller allows a namespace administrator to exfiltrate sensitive secret contents by manipulating cross-namespace resource references.</description><content:encoded><![CDATA[<p>CVE-2026-66878 describes an information disclosure vulnerability within the multicloud-operators-subscription component, often utilized in Red Hat Advanced Cluster Management for Kubernetes. The flaw resides in the subscription and channel resource management logic, specifically involving the Channel.Spec.SecretRef.Namespace field. An attacker with existing namespace administrator privileges can abuse this field to reference and copy Kubernetes Secrets from namespaces they would otherwise be unauthorized to access. By creating or updating Channel and Subscription objects with specifically crafted references, the controller performs the unauthorized copy operation, effectively exposing sensitive information such as credentials, tokens, or encryption keys. This vulnerability poses a significant risk to multi-tenant environments where strict namespace isolation is required.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized disclosure of sensitive information stored in Kubernetes Secrets. In multi-tenant cloud environments, this allows an attacker with limited administrative access over a single namespace to exfiltrate secrets from other namespaces, potentially leading to full compromise of interconnected systems or downstream services relying on the leaked credentials.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the multicloud-operators-subscription component to the patched version provided by Red Hat as soon as it becomes available. In the interim, restrict the ability for users to create or modify Channel and Subscription resources via Kubernetes RBAC to only trusted cluster-level administrators. Review existing audit logs for the creation of Channel resources that reference cross-namespace Secrets.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>