CVE-2026-93017
Received
Received - Intake
Privilege Escalation via Secrets Access in Insights Operator
Vulnerability report for CVE-2026-93017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: redhat-SADP
Description
Description
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction β therefore, access to every secret in every namespace in the cluster.
Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373
```
- apiGroups:
- ""
resources:
- secrets
verbs:
- get
- list
```
By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.
```
spec:
serviceAccountName:"gather"
```
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| red_hat | insights-operator | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |