{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/red-hat-advanced-cluster-management-for-kubernetes/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-17107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat Advanced Cluster Management for Kubernetes","multicluster-engine"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","vulnerability","kubernetes","cloud","red-hat"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA high-severity vulnerability, CVE-2026-17107, has been identified in the \u003ccode\u003ecluster-proxy service-proxy\u003c/code\u003e component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). This flaw enables an authenticated hub principal to achieve \u003ccode\u003ecluster-admin\u003c/code\u003e privileges across all managed clusters. The \u003ccode\u003eservice-proxy\u003c/code\u003e component is designed to append impersonation group headers to proxied requests but fails to adequately remove or validate caller-supplied values. Attackers can exploit this by injecting a malicious \u003ccode\u003eImpersonate-Group\u003c/code\u003e header, such as \u003ccode\u003esystem:masters\u003c/code\u003e. Coupled with the unrestricted impersonation permissions held by the spoke ServiceAccount, this bypasses authorization checks, allowing unauthorized privilege escalation. This vulnerability poses a significant risk to the security and integrity of environments utilizing RHACM or MCE, as it grants full administrative control over critical Kubernetes resources.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access\u003c/strong\u003e: An attacker gains authenticated access as a hub principal to the Red Hat Advanced Cluster Management or Multicluster Engine platform.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eVulnerability Identification\u003c/strong\u003e: The authenticated attacker identifies the \u003ccode\u003ecluster-proxy service-proxy\u003c/code\u003e component as vulnerable, specifically its failure to validate or remove caller-supplied \u003ccode\u003eImpersonate-Group\u003c/code\u003e headers.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRequest Crafting\u003c/strong\u003e: The attacker crafts a malicious proxied request intended for a managed cluster, embedding a forged \u003ccode\u003eImpersonate-Group: system:masters\u003c/code\u003e header within it.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eHeader Injection\u003c/strong\u003e: The crafted request, containing the malicious header, is sent to the \u003ccode\u003ecluster-proxy service-proxy\u003c/code\u003e component.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLack of Validation\u003c/strong\u003e: The \u003ccode\u003eservice-proxy\u003c/code\u003e processes the request and, due to the identified flaw, appends the attacker-supplied \u003ccode\u003eImpersonate-Group\u003c/code\u003e header without proper validation or prior removal of existing values.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivilege Escalation via Spoke ServiceAccount\u003c/strong\u003e: The proxied request, now containing the injected \u003ccode\u003esystem:masters\u003c/code\u003e group, reaches the target managed cluster. The spoke ServiceAccount, which possesses unrestricted impersonation permissions, processes this request with \u003ccode\u003ecluster-admin\u003c/code\u003e privileges.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAdministrative Control\u003c/strong\u003e: The attacker successfully escalates privileges and gains \u003ccode\u003ecluster-admin\u003c/code\u003e access on the managed cluster, enabling full control over all Kubernetes resources and configurations within that cluster.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-17107 allows an authenticated attacker to gain \u003ccode\u003ecluster-admin\u003c/code\u003e privileges on all managed clusters within the Red Hat Advanced Cluster Management or Multicluster Engine environment. This grants full administrative control, potentially leading to complete compromise of the clusters, including data exfiltration, service disruption, deployment of malicious workloads, or further lateral movement within the compromised infrastructure. Given the critical role of cluster-admin privileges, this vulnerability could severely impact the confidentiality, integrity, and availability of the affected Kubernetes environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-17107 by updating Red Hat Advanced Cluster Management for Kubernetes and multicluster-engine to the versions specified in the vendor advisory from Red Hat.\u003c/li\u003e\n\u003cli\u003eMonitor platform logs for the \u003ccode\u003ecluster-proxy service-proxy\u003c/code\u003e component for any unusual \u003ccode\u003eImpersonate-Group\u003c/code\u003e headers in proxied requests, particularly those not originating from known legitimate internal services.\u003c/li\u003e\n\u003cli\u003eReview and restrict ServiceAccount permissions within your Kubernetes environment to follow the principle of least privilege, especially for ServiceAccounts involved in proxying or impersonation, to limit the blast radius of similar vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T19:18:59Z","date_published":"2026-07-24T19:18:59Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-17107-rhacm/","summary":"A flaw exists in the cluster-proxy service-proxy component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE), allowing an authenticated hub principal to inject an Impersonate-Group header into proxied requests, bypassing validation, and leveraging the spoke ServiceAccount's unrestricted impersonation permissions to escalate privileges to cluster-admin on all managed clusters.","title":"Red Hat Advanced Cluster Management Vulnerability Allows Cluster-Admin Privilege Escalation","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-17107-rhacm/"}],"language":"en","title":"CraftedSignal Threat Feed - Red Hat Advanced Cluster Management for Kubernetes","version":"https://jsonfeed.org/version/1.1"}