CVE-2026-67567: Red Hat Advanced Cluster Management For Kubernetes 2.11

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263584 (fixed in 1787263584)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787263693 (fixed in 1787263693)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787170830 (fixed in 1787170830)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787240030 (fixed in 1787240030)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787242321 (fixed in 1787242321)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787242108 (fixed in 1787242108)

Published 2026-08-20. Last modified 2026-08-28.