Executive brief
A flaw in Red Hat's multicloud-operators-subscription component allows users on a managed Kubernetes cluster to escalate their privileges by creating malicious resource annotations. Successful attacks grant full cluster control, enabling unauthorized deployment of workloads across all namespaces and potential theft or manipulation of sensitive data and applications running in the cluster.
Technical details
This is a privilege escalation vulnerability in the multicloud-operators-subscription component affecting Kubernetes cluster management. An authenticated user on a managed cluster can craft a Subscription resource with specially designed annotations that bypass authorization controls, allowing them to execute code with the Service Account privileges of the subscription controller. This grants unrestricted access to deploy and modify resources across all cluster namespaces. The vulnerability requires local cluster access but no elevated initial privileges, and patches are expected from Red Hat.
Affected products
- Red Hat multicloud-operators-subscription <UNKNOWN>
Timeline
- 2026-08-17: disclosed