CVE-2026-17107: Red Hat Multicluster Engine For Kubernetes 2.10
High severity, CVSS 8.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.
Affected products
- Red Hat Multicluster Engine For Kubernetes 2.10: before 1784342329 (fixed in 1784342329)
- Red Hat Multicluster Engine For Kubernetes 2.11: before 1784925025 (fixed in 1784925025)
- Red Hat Multicluster Engine For Kubernetes 2.17: before 1784926298 (fixed in 1784926298)
- Red Hat Multicluster Engine For Kubernetes 2.6: before 1783985960 (fixed in 1783985960)
- Red Hat Multicluster Engine For Kubernetes 2.8: before 1784342329 (fixed in 1784342329)
- Red Hat Multicluster Engine For Kubernetes 2.9: before 1783278220 (fixed in 1783278220)
Published 2026-07-24. Last modified 2026-09-29.