Executive brief
insights-client is a Red Hat component deployed as a pod in Kubernetes clusters that monitors system health and configuration. Its service account has been granted excessive permissions to read all secrets cluster-wide, far beyond what the component actually needs. If the insights-client pod or its credentials are compromised, an attacker could read sensitive data including kubeconfigs and authentication tokens from all clusters managed by the hub.
Technical details
This vulnerability is a privilege escalation issue stemming from over-permissioned Kubernetes RBAC (Role-Based Access Control). The insights-client ServiceAccount is bound to a ClusterRole that grants get, list, and watch permissions on all secrets cluster-wide, while the actual code only requires read access to a single specific secret. The attack vector requires compromise of either the insights-client pod or theft of its service account token (which could occur via pod escape, compromised container image, or node-level access). A successful attack grants an attacker read access to all secrets in the Kubernetes cluster, potentially exposing kubeconfigs for managed clusters and other sensitive credentials. The fix reduces the ClusterRole permissions to the minimum required—access only to the specific secret needed by the component.
Affected products
- Red Hat Advanced Cluster Management for Kubernetes v2.17.1
Timeline
- 2026-08-26: disclosed
- 2026-09-01: patched