PatchSiren cyber security CVE debrief
CVE-2026-10090 Red Hat CVE debrief
A critical vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes 2, allowing a user with namespace-scoped 'edit' privileges to escalate privileges to full cluster-admin. This issue arises from the Application Subscription controller's failure to verify role and restrict resources, enabling an attacker to include cluster-scoped resources in a Helm chart.
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-09-08
Who should care
ACM hub namespace administrators, Kubernetes cluster administrators, and users with 'edit' privileges in ACM hub namespaces should assess exposure and take necessary actions to restrict privileges and apply errata.
Why it matters
CVE-2026-10090 is a critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2, allowing users with namespace-scoped 'edit' privileges to escalate to full cluster-admin privilege. ACM hub namespace administrators and Kubernetes cluster administrators should assess exposure and take immediate action to restrict privileges and apply Red Hat errata.
- Privilege escalation to cluster-admin
- Potential for unauthorized access to Kubernetes clusters
- Need for immediate attention to restrict user privileges
- Verification of Red Hat errata application required
Technical summary
The Application Subscription controller in Red Hat Advanced Cluster Management for Kubernetes 2 does not properly verify user privileges when creating Channel and Subscription resources. This allows a user with namespace-scoped 'edit' privileges to create a Channel pointing to a controlled Helm repository and a Subscription referencing it, potentially leading to privilege escalation. The vulnerability arises from the controller's failure to restrict applied resources to the subscription namespace and verify whether the subscription creator holds the 'open-cluster-management:subscription-admin' role. Successful exploitation results in full cluster-admin privilege escalation, allowing the attacker to include in
Defensive priority
Immediate attention is required for ACM hub namespace administrators to assess exposure and restrict privileges.
Recommended defensive actions
- Assess exposure in ACM hub namespaces
- Restrict privileges for users with namespace-scoped 'edit' privileges
- Verify and apply Red Hat errata RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, RHSA-2026:60391
- Monitor for suspicious activity in ACM environments
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 9 and critical severity. Red Hat has released several errata related to this issue, including RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, and RHSA-2026:60391. The vulnerability allows users with namespace-scoped 'edit' privileges to escalate to full cluster-admin privilege. It is essential to assess exposure and take immediate action to restrict privileges and apply Red Hat errata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-10090 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-10090
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-10090 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10090
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60386
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60387
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60388
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60389
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60390
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60391
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-10090
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.