No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, Red Hat Advanced Cluster Management for Kubernetes administrators should configure the application-manager addon to use the least-privilege RBAC variant. This involves applying the addon/manifests/permission/role.yaml configuration, which restricts the permissions granted to the application-manager ServiceAccount. Consult Red Hat documentation for specific instructions on how to apply custom RBAC configurations for RHACM addons. Applying this change may require a restart or reload of the affected components to take effect.
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster. | |
| Title | Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-250 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T19:41:18.859Z
Reserved: 2026-08-11T17:40:07.962Z
Link: CVE-2026-72508
No data.
Status : Received
Published: 2026-08-12T20:17:49.650
Modified: 2026-08-12T20:17:49.650
Link: CVE-2026-72508
No data.
OpenCVE Enrichment
No data.