Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Red Hat ACM Flaw Allows Cluster-Admin Access

Critical Red Hat ACM Flaw Allows Cluster-Admin Access

Posted on August 10, 2026 By CWS

Red Hat has announced a serious security vulnerability, identified as CVE-2026-10090, within its Advanced Cluster Management for Kubernetes (ACM) software. This flaw, located in the Application Subscription controller, poses a significant risk as it could allow unauthorized users to elevate their privileges to gain full cluster-admin access.

Understanding the Vulnerability

Rated as Important with a CVSS score of 9.9, the vulnerability affects users with namespace-scoped “edit” permissions on an ACM hub. These users could potentially escalate their privileges, granting them control over the entire cluster environment. The issue stems from the multicluster-operators-subscription component, which is integral to ACM’s Application Subscription feature.

According to Red Hat, a user with basic edit rights in a hub namespace can exploit this flaw by creating a Channel resource linked to a personally controlled Helm repository. This would then connect to a Subscription resource referencing the same channel. Critically, the controller processes these requests with elevated permissions without verifying if the user has the necessary “open-cluster-management:subscription-admin” role.

Implications of the Security Flaw

The absence of proper authorization checks allows attackers to include cluster-scoped objects in their Helm charts, such as a ClusterRoleBinding. This binding can connect their ServiceAccount to the “cluster-admin” ClusterRole, effectively granting full administrative privileges upon application by the controller.

Classified under CWE-267, Privilege Defined With Unsafe Actions, this flaw is documented as Bugzilla entry 2483292. Its severity is underscored by the fact that it contradicts ACM’s security model, which restricts non-admin users to deploying resources within their own namespaces.

Protecting Against Potential Exploits

Organizations using ACM for multi-tenant separation across managed clusters could inadvertently expose their environments to exploitation by users with mere edit-level access. This access is often broadly granted to developers, increasing the risk of widespread control over clustered resources.

Red Hat has highlighted that no straightforward mitigation currently aligns with their deployment and stability requirements. The affected package is identified as rhacm2/multicluster-operators-subscription-rhel9 in Red Hat ACM for Kubernetes 2, with its status marked as “Affected.”

In the absence of an official patch, Red Hat advises security teams to audit namespace-scoped edit permissions, monitor the creation of Channel and Subscription resources, and limit subscription-admin rights to trusted personnel. Additionally, implementing admission control policies to block cluster-scoped resources during application subscriptions is recommended as a temporary safeguard.

As Red Hat works on a comprehensive solution, organizations must remain vigilant to prevent potential exploitation of this critical vulnerability.

Cyber Security News Tags:ACM, cluster-admin, CVE-2026-10090, Cybersecurity, Helm, Kubernetes, multicluster operators, privilege escalation, Red Hat, Security, Vulnerability

Post navigation

Previous Post: GitHub Enhances Malware Detection Across Multiple Ecosystems
Next Post: Stealth Loaders in Google Play Apps Deliver Anatsa Malware

Related Posts

Node.js Developers Face Advanced Social Engineering Threat Node.js Developers Face Advanced Social Engineering Threat Cyber Security News
Threat Actors Using AI to Scale Operations, Accelerate Attacks and Attack Autonomous AI Agents Threat Actors Using AI to Scale Operations, Accelerate Attacks and Attack Autonomous AI Agents Cyber Security News
Google Urges Chrome Update to Block Critical Threats Google Urges Chrome Update to Block Critical Threats Cyber Security News
Stealthy WordPress Malware Deliver Windows Trojan via PHP Backdoor Stealthy WordPress Malware Deliver Windows Trojan via PHP Backdoor Cyber Security News
New Black-Hat AI Tool Used by Hackers to Launch Cyberattacks New Black-Hat AI Tool Used by Hackers to Launch Cyberattacks Cyber Security News
Breaking Message Queuing (MSMQ) Functionality Affects IIS Sites Breaking Message Queuing (MSMQ) Functionality Affects IIS Sites Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Stealth Loaders in Google Play Apps Deliver Anatsa Malware
  • Critical Red Hat ACM Flaw Allows Cluster-Admin Access
  • GitHub Enhances Malware Detection Across Multiple Ecosystems
  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Stealth Loaders in Google Play Apps Deliver Anatsa Malware
  • Critical Red Hat ACM Flaw Allows Cluster-Admin Access
  • GitHub Enhances Malware Detection Across Multiple Ecosystems
  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark