Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-10090: Red Hat ACM: Privilege Escalation through Helm Chart
CVE-2026-10090
CVE-2026-10090
Summary
A flaw in Red Hat Advanced Cluster Management for Kubernetes (ACM) allows a user with edit privileges to create a subscription that grants them full control over the cluster. This happens because ACM doesn't properly verify who can deploy resources. To fix this, users should ensure only authorized personnel have access to subscription creation and deployment.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
Original title
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" pr...
Original description
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the "open-cluster-management:subscription-admin" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the "cluster-admin" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.
nvd CVSS3.1
9.9
Vulnerability type
CWE-267
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026