Executive brief
Red Hat Advanced Cluster Security (RHACS) is a Kubernetes security platform used to monitor and protect containerized applications. A flaw in its machine-to-machine token authentication system allows attackers with valid credentials to bypass role restrictions and gain unauthorized administrative privileges, potentially compromising container security policies and access controls across an organization's Kubernetes infrastructure.
Technical details
The vulnerability is a permissive regular expression (CWE-625) flaw in RHACS Central's machine-to-machine (M2M) OIDC token exchange mechanism. When administrators configure M2M role mappings, the system fails to anchor regex patterns (missing `^` and `
Affected products
- Red Hat Advanced Cluster Security for Kubernetes <UNKNOWN>
Timeline
- 2026-08-10: disclosed