Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72508: Red Hat Advanced Cluster Management: Privilege Escalation Risk

CVE-2026-72508 · published 22 days ago
Summary

A vulnerability in Red Hat Advanced Cluster Management allows a tenant with limited access to gain high-level privileges and potentially execute arbitrary code on the cluster. This can happen when a tenant creates custom resources that use a highly privileged account. To mitigate this risk, update to the latest version of Red Hat Advanced Cluster Management and ensure proper configuration of service accounts and access controls.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat red hat advanced cluster management for kubernetes 2 All versions
red hat red hat advanced cluster management for kubernetes 2.13 All versions
red hat red hat advanced cluster management for kubernetes 2.15 All versions
red hat red hat advanced cluster management for kubernetes 2.17 All versions
Original advisory text
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy a...
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
References
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-250Execution with Unnecessary Privileges
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Sources
CVE-2026-72508 · MITRE
Monitor software like this
Free during beta