Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-66792Escalación de privilegios en multicloud-operators-subscription

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

Ver en NVD

Análisis

Critical vulnerability in multicloud-operators-subscription (part of RHACM/OCM). An attacker on a managed cluster can use crafted annotations to escalate privileges and deploy resources into any namespace using the controller's Service Account permissions.

Roles relevantes

KubernetesCloudCyberSecurityBackendDockerLinux

Severidad

Puntaje: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-863

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

Publicada: 17/8/2026, 19:16:34
Última modificación: 17/8/2026, 19:16:34

Referencias

InicioEventosBlogRecursosCursosEquipo