Executive brief
Red Hat Advanced Cluster Management for Kubernetes is a platform that manages and secures containers and clusters across multiple cloud environments from a single console. This vulnerability allows a user with limited permissions to improperly access and modify sensitive configuration secrets across different cluster namespaces, potentially leading to unauthorized access or privilege escalation within managed Kubernetes environments.
Technical details
The multicloud-operators-channel component in Red Hat Advanced Cluster Management for Kubernetes contains a privilege escalation vulnerability that allows authenticated users with specific permissions to manipulate how Kubernetes Secrets are handled across namespace boundaries. The flaw enables an attacker to modify Secrets in unauthorized namespaces, potentially gaining elevated privileges or accessing sensitive configuration data. The vulnerability requires existing authentication and specific user permissions to exploit. A patch is available in Red Hat Advanced Cluster Management v2.17.1 and later, as detailed in RHSA-2026:60386.
Affected products
- Red Hat Advanced Cluster Management for Kubernetes <2.17.1
Timeline
- 2026-08-12: disclosed
- 2026-08-26: advisory
- 2026-08-26: patched: Fix available in Red Hat Advanced Cluster Management v2.17.1