CVE-2026-72508: Red Hat Advanced Cluster Management For Kubernetes 2.11
Critical severity, CVSS 9.9. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263584 (fixed in 1787263584)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787263693 (fixed in 1787263693)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787170830 (fixed in 1787170830)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787240030 (fixed in 1787240030)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787242321 (fixed in 1787242321)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787242108 (fixed in 1787242108)
Published 2026-08-12. Last modified 2026-08-27.