A critical privilege escalation flaw, tracked as CVE-2026-10090 with a CVSS score of 9.9, was discovered in Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a user with namespace edit rights to seize full cluster-admin control by exploiting the Application Subscription controller's failure to check for the 'subscription-admin' role and confine applied resources to the subscription namespace. As a result, an attacker can smuggle in cluster-scoped resources and bind their ServiceAccount to cluster-admin via ClusterRoleBinding, contradicting documented behavior for non-admin users. The flaw affects Red Hat Advanced Cluster Management for Kubernetes, with no confirmed exploitation yet reported. This vulnerability has significant business impact as it enables an attacker to gain total control of the system, which is a top level of access in ACM. It is essential to apply Red Hat's updates as soon as they are available and limit who holds namespace 'edit' rights on ACM hub namespaces to mitigate this issue.
We recommend you to update Red Hat Advanced Cluster Management for Kubernetes to version 2.[/subscribe_to_unlock_form]
A critical privilege escalation flaw, tracked as CVE-2026-10090 with a CVSS score of 9.9, was discovered in Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a user with namespace edit rights to seize full cluster-admin control by exploiting the Application Subscription controller's failure to check for the 'subscription-admin' role and confine applied resources to the subscription namespace. As a result, an attacker can smuggle in cluster-scoped resources and bind their ServiceAccount to cluster-admin via ClusterRoleBinding, contradicting documented behavior for non-admin users. The flaw affects Red Hat Advanced Cluster Management for Kubernetes, with no confirmed exploitation yet reported. This vulnerability has significant business impact as it enables an attacker to gain total control of the system, which is a top level of access in ACM. It is essential to apply Red Hat's updates as soon as they are available and limit who holds namespace 'edit' rights on ACM hub namespaces to mitigate this issue.
We recommend you to update Red Hat Advanced Cluster Management for Kubernetes to version 2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]