CVE-2026-72508: Red Hat Advanced Cluster Management For Kubernetes 2.11

Critical severity, CVSS 9.9. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263584 (fixed in 1787263584)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787263693 (fixed in 1787263693)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787170830 (fixed in 1787170830)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787240030 (fixed in 1787240030)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787242321 (fixed in 1787242321)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787242108 (fixed in 1787242108)

Published 2026-08-12. Last modified 2026-08-27.