Kryptovalutaticker:
sysadmin från Cyber Security News

Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access

Guru Baran
Monday at 14:46
17 Visningar
0 Kommentarer
Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access

Red Hat has disclosed a critical privilege escalation flaw, tracked as CVE-2026-10090, affecting the Application Subscription controller in Red Hat Advanced Cluster Management for Kubernetes (ACM). Rated Important with a CVSS score of 9.9, the vulnerability allows a user with only namespace-scoped “edit” permissions on an ACM hub to escalate all the way to full cluster-admin rights, effectively handing low-privilege insiders control over the entire managed cluster fleet . The bug resides in the multicluster-operators-subscription component, which powers ACM’s Application Subscription feature. According to Red Hat’s advisory, a user holding basic edit privileges in a hub namespace can create a Channel resource...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!