CVE-2026-72508

Red Hat · Red Hat Advanced Cluster Management for Kubernetes 2

A confused-deputy vulnerability in Red Hat Advanced Cluster Management allows namespace-admin tenants to escalate privileges by leveraging highly privileged ServiceAccounts.

Executive summary

A critical confused-deputy vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2 enables namespace-level administrators to achieve cluster-wide privilege escalation.

Vulnerability

The flaw exists in the multicloud-operators-subscription component, where a namespace-admin tenant can create Subscription Custom Resources that misuse a highly privileged ServiceAccount. This allows the tenant to perform a confused-deputy attack, effectively executing actions with privileges far exceeding their intended scope.

Business impact

With a CVSS score of 9.9, this vulnerability represents an extreme risk to the integrity and confidentiality of the entire cluster. By escalating privileges, an attacker can deploy arbitrary cluster-scoped resources and potentially execute arbitrary code. This could lead to a total compromise of the management environment, unauthorized access to cross-cluster data, and the ability to manipulate infrastructure beyond the attacker's assigned namespace.

Remediation

Immediate Action: Consult the vendor advisory at https://access.redhat.com/security/cve/CVE-2026-72508 and install the latest security updates for Red Hat Advanced Cluster Management.

Proactive Monitoring: Monitor for the creation of suspicious Subscription Custom Resources, particularly those referencing high-privilege ServiceAccounts.

Compensating Controls: Restrict the ability of namespace-level admins to define or modify Subscription resources until the platform is updated.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability highlights a significant risk of lateral movement and privilege escalation within multi-tenant cluster environments. Security teams must ensure that the latest patches are applied immediately to prevent namespace-level users from gaining unauthorized control over the broader cluster infrastructure.

More Red Hat CVEs