CVE-2026-66792
Received Received - Intake

Privilege Escalation in multicloud-operators-subscription

Vulnerability report for CVE-2026-66792, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: redhat-SADP

Description

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat multicloud-operators-subscription *
red_hat multicloud_operators_subscription *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management for Kubernetes. It allows a user on a managed cluster to escalate privileges by creating a Subscription with specific crafted annotations. Successful exploitation lets the attacker deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and full control over cluster resources.

Detection Guidance

Check for Subscriptions with crafted annotations like apps.open-cluster-management.io/hosting-subscription and apps.open-cluster-management.io/cluster-admin: true. Inspect logs for unauthorized resource deployments across namespaces.

Impact Analysis

An attacker could gain unauthorized access to cluster resources, deploy malicious resources across namespaces, and take full control of the cluster. This could lead to data breaches, service disruptions, or further compromise of the Kubernetes environment.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements for GDPR, HIPAA, and other regulations. It may result in legal penalties, loss of trust, and reputational damage due to compromised data integrity and confidentiality.

Mitigation Strategies

Monitor for suspicious Subscription creations. Restrict user permissions on managed clusters. Apply network policies to limit cross-namespace access. Monitor for unauthorized resource deployments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66792. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart