Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-72508: Red Hat Advanced Cluster Management: Privilege Escalation Risk
CVE-2026-72508 · published 22 days ago
Summary
A vulnerability in Red Hat Advanced Cluster Management allows a tenant with limited access to gain high-level privileges and potentially execute arbitrary code on the cluster. This can happen when a tenant creates custom resources that use a highly privileged account. To mitigate this risk, update to the latest version of Red Hat Advanced Cluster Management and ensure proper configuration of service accounts and access controls.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
| red hat | red hat advanced cluster management for kubernetes 2.13 | All versions |
| red hat | red hat advanced cluster management for kubernetes 2.15 | All versions |
| red hat | red hat advanced cluster management for kubernetes 2.17 | All versions |
Original advisory text
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy a...
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
References
- https://access.redhat.com/security/cve/CVE-2026-72508 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2514225 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60386 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60389 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60390 vendor-advisory x_refsource_REDHAT
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-250Execution with Unnecessary Privileges
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta