Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-67567: Multicloud Operators Subscription lets tenant deploy any resource
CVE-2026-67567 · published 14 days ago
Summary
The Multicloud Operators Subscription component lets a user who can create HelmRelease objects run Helm charts with high‑privilege permissions. Because the system does not check what the chart contains, that user can create any kind of resource anywhere in the cluster. To protect your environment, restrict who can create HelmRelease objects and run the component with a limited service account or apply stricter validation policies.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
Original advisory text
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing securit...
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.
References
- https://access.redhat.com/security/cve/CVE-2026-67567 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2514224 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60386
- https://access.redhat.com/errata/RHSA-2026:60389
- https://access.redhat.com/errata/RHSA-2026:60390
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Monitor software like this
Free during beta