Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Red Hat ACM Flaw Allows Cluster-Admin Access

Critical Red Hat ACM Flaw Allows Cluster-Admin Access

Posted on August 10, 2026 By CWS

Red Hat has announced a serious security vulnerability, identified as CVE-2026-10090, within its Advanced Cluster Management for Kubernetes (ACM) software. This flaw, located in the Application Subscription controller, poses a significant risk as it could allow unauthorized users to elevate their privileges to gain full cluster-admin access.

Understanding the Vulnerability

Rated as Important with a CVSS score of 9.9, the vulnerability affects users with namespace-scoped “edit” permissions on an ACM hub. These users could potentially escalate their privileges, granting them control over the entire cluster environment. The issue stems from the multicluster-operators-subscription component, which is integral to ACM’s Application Subscription feature.

According to Red Hat, a user with basic edit rights in a hub namespace can exploit this flaw by creating a Channel resource linked to a personally controlled Helm repository. This would then connect to a Subscription resource referencing the same channel. Critically, the controller processes these requests with elevated permissions without verifying if the user has the necessary “open-cluster-management:subscription-admin” role.

Implications of the Security Flaw

The absence of proper authorization checks allows attackers to include cluster-scoped objects in their Helm charts, such as a ClusterRoleBinding. This binding can connect their ServiceAccount to the “cluster-admin” ClusterRole, effectively granting full administrative privileges upon application by the controller.

Classified under CWE-267, Privilege Defined With Unsafe Actions, this flaw is documented as Bugzilla entry 2483292. Its severity is underscored by the fact that it contradicts ACM’s security model, which restricts non-admin users to deploying resources within their own namespaces.

Protecting Against Potential Exploits

Organizations using ACM for multi-tenant separation across managed clusters could inadvertently expose their environments to exploitation by users with mere edit-level access. This access is often broadly granted to developers, increasing the risk of widespread control over clustered resources.

Red Hat has highlighted that no straightforward mitigation currently aligns with their deployment and stability requirements. The affected package is identified as rhacm2/multicluster-operators-subscription-rhel9 in Red Hat ACM for Kubernetes 2, with its status marked as “Affected.”

In the absence of an official patch, Red Hat advises security teams to audit namespace-scoped edit permissions, monitor the creation of Channel and Subscription resources, and limit subscription-admin rights to trusted personnel. Additionally, implementing admission control policies to block cluster-scoped resources during application subscriptions is recommended as a temporary safeguard.

As Red Hat works on a comprehensive solution, organizations must remain vigilant to prevent potential exploitation of this critical vulnerability.

Cyber Security News Tags:ACM, cluster-admin, CVE-2026-10090, Cybersecurity, Helm, Kubernetes, multicluster operators, privilege escalation, Red Hat, Security, Vulnerability

Post navigation

Previous Post: GitHub Enhances Malware Detection Across Multiple Ecosystems
Next Post: Stealth Loaders in Google Play Apps Deliver Anatsa Malware

Related Posts

WhatsApp Introduces Handles for Enhanced Privacy WhatsApp Introduces Handles for Enhanced Privacy Cyber Security News
Threat Actors can Use Xanthorox AI Tool to Generate Different Malicious Code Based on Prompts Threat Actors can Use Xanthorox AI Tool to Generate Different Malicious Code Based on Prompts Cyber Security News
Google’s reCAPTCHA Update Challenges Privacy Advocates Google’s reCAPTCHA Update Challenges Privacy Advocates Cyber Security News
RMM Tools: Vital for IT but Increasingly Misused by Hackers RMM Tools: Vital for IT but Increasingly Misused by Hackers Cyber Security News
Unpatched BitLocker Flaws Expose Windows Systems Unpatched BitLocker Flaws Expose Windows Systems Cyber Security News
Critical Ruby Flaw Could Lead to System Takeover Critical Ruby Flaw Could Lead to System Takeover Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform
  • AI Search Poisoning and Security Risks: Key Cyber News
  • Hackers Target Critical VPN Flaws in Check Point Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform
  • AI Search Poisoning and Security Risks: Key Cyber News
  • Hackers Target Critical VPN Flaws in Check Point Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark