CVE-2026-66792

9.9

Red Hat · Multicluster Global Hub

A privilege escalation vulnerability in the multicloud-operators-subscription component allows users to deploy resources with elevated permissions via crafted Subscription annotations.

Executive summary

This critical vulnerability in Red Hat Multicluster Global Hub and Advanced Cluster Management for Kubernetes allows an authenticated user to escalate privileges and gain unauthorized control over cluster resources.

Vulnerability

The flaw exists in the multicloud-operators-subscription component, which fails to properly sanitize user-provided annotations. An authenticated user on a managed cluster can leverage these annotations to deploy resources into any namespace using the controller's elevated Service Account permissions.

Business impact

The vulnerability carries a CVSS score of 9.9, reflecting its critical severity. Successful exploitation permits an attacker to bypass security boundaries and achieve full administrative control over managed clusters, leading to potential data exfiltration, service disruption, and total compromise of the containerized environment.

Remediation

Immediate Action: Update Red Hat Multicluster Global Hub and Red Hat Advanced Cluster Management for Kubernetes to the latest available version provided by the vendor.

Proactive Monitoring: Review cluster access logs for anomalous Subscription creation events or unauthorized resource deployments in restricted namespaces.

Compensating Controls: Implement strict Kubernetes Network Policies and Role-Based Access Control (RBAC) to limit the impact of compromised service accounts while the update process is underway.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this privilege escalation flaw, administrators must prioritize patching across all managed clusters immediately. Failure to update leaves the infrastructure vulnerable to full cluster compromise by any user with subscription creation rights.

More Red Hat CVEs