PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10090 Red Hat CVE debrief

A critical vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes 2, allowing a user with namespace-scoped 'edit' privileges to escalate privileges to full cluster-admin. This issue arises from the Application Subscription controller's failure to verify role and restrict resources, enabling an attacker to include cluster-scoped resources in a Helm chart.

Vendor
Red Hat
Product
Red Hat Advanced Cluster Management for Kubernetes 2
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-09-08
Advisory published
2026-08-05
Advisory updated
2026-09-08

Who should care

ACM hub namespace administrators, Kubernetes cluster administrators, and users with 'edit' privileges in ACM hub namespaces should assess exposure and take necessary actions to restrict privileges and apply errata.

Why it matters

CVE-2026-10090 is a critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2, allowing users with namespace-scoped 'edit' privileges to escalate to full cluster-admin privilege. ACM hub namespace administrators and Kubernetes cluster administrators should assess exposure and take immediate action to restrict privileges and apply Red Hat errata.

  • Privilege escalation to cluster-admin
  • Potential for unauthorized access to Kubernetes clusters
  • Need for immediate attention to restrict user privileges
  • Verification of Red Hat errata application required

Technical summary

The Application Subscription controller in Red Hat Advanced Cluster Management for Kubernetes 2 does not properly verify user privileges when creating Channel and Subscription resources. This allows a user with namespace-scoped 'edit' privileges to create a Channel pointing to a controlled Helm repository and a Subscription referencing it, potentially leading to privilege escalation. The vulnerability arises from the controller's failure to restrict applied resources to the subscription namespace and verify whether the subscription creator holds the 'open-cluster-management:subscription-admin' role. Successful exploitation results in full cluster-admin privilege escalation, allowing the attacker to include in

Defensive priority

Immediate attention is required for ACM hub namespace administrators to assess exposure and restrict privileges.

Recommended defensive actions

  • Assess exposure in ACM hub namespaces
  • Restrict privileges for users with namespace-scoped 'edit' privileges
  • Verify and apply Red Hat errata RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, RHSA-2026:60391
  • Monitor for suspicious activity in ACM environments
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 9 and critical severity. Red Hat has released several errata related to this issue, including RHSA-2026:60386, RHSA-2026:60387, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60390, and RHSA-2026:60391. The vulnerability allows users with namespace-scoped 'edit' privileges to escalate to full cluster-admin privilege. It is essential to assess exposure and take immediate action to restrict privileges and apply Red Hat errata.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10090 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10090

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10090 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10090

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.