Junglewise Threat Intelligence

CVE-2026-66878: Red Hat multicloud-operators-subscription privilege escalation

CVE-2026-66878 · Severity: high · CVSS 7.7 · Published 2026-08-12

Vendors: Red Hat.

Executive brief

Red Hat's multicloud-operators-subscription is a component of Advanced Cluster Management for Kubernetes that manages cross-cluster resources. A namespace administrator can exploit a flaw in how the system handles secret references to access sensitive credentials stored in other namespaces, potentially exposing database passwords, API keys, and other confidential data outside their authorized scope.

Technical details

The vulnerability is a privilege escalation/information disclosure flaw in multicloud-operators-subscription's Channel and Subscription resource handlers. A privileged user (namespace administrator) with permission to create Channel and Subscription resources can manipulate the Channel.Spec.SecretRef.Namespace field to cause the system to copy sensitive Secret contents from arbitrary namespaces into their own namespace. This occurs due to insufficient namespace boundary enforcement in the secret reference resolution logic. The attack requires existing administrative privileges within a namespace but allows disclosure of secrets outside the attacker's authorized scope. Patches are available in Red Hat Advanced Cluster Management for Kubernetes v2.17.1.

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes 2.17.0 and earlier

Timeline

  • 2026-08-12: disclosed
  • 2026-08-26: advisory: Red Hat Security Advisory RHSA-2026:60386 issued
  • 2026-08-26: patched: Fix available in ACM 2.17.1

References