Junglewise Threat Intelligence

CVE-2026-66792: Red Hat multicloud-operators-subscription privilege escalation

CVE-2026-66792 · Severity: critical · CVSS 9.9 · Published 2026-08-17

Vendors: Red Hat.

Executive brief

A flaw in Red Hat's multicloud-operators-subscription component allows users on a managed Kubernetes cluster to escalate their privileges by creating malicious resource annotations. Successful attacks grant full cluster control, enabling unauthorized deployment of workloads across all namespaces and potential theft or manipulation of sensitive data and applications running in the cluster.

Technical details

This is a privilege escalation vulnerability in the multicloud-operators-subscription component affecting Kubernetes cluster management. An authenticated user on a managed cluster can craft a Subscription resource with specially designed annotations that bypass authorization controls, allowing them to execute code with the Service Account privileges of the subscription controller. This grants unrestricted access to deploy and modify resources across all cluster namespaces. The vulnerability requires local cluster access but no elevated initial privileges, and patches are expected from Red Hat.

Affected products

  • Red Hat multicloud-operators-subscription <UNKNOWN>

Timeline

  • 2026-08-17: disclosed

References