PatchSiren cyber security CVE debrief
CVE-2026-107176 Red Hat CVE debrief
A flaw in the cluster-samples-operator allows unauthorized access to all secrets in the openshift-config namespace if the samples-operator pod or its service account token is compromised. This issue arises from the RBAC Role coreos-pull-secret-reader granting excessive permissions on all Secret resources without proper scoping. The vulnerability could lead to exposure of sensitive cluster configuration, including OAuth identity provider credentials and cloud provider credentials. Defenders should prioritize verifying the integrity of the samples-operator pod and its service account, assessing exposure to potential compromise, and ensuring that only necessary permissions are granted
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for securing the openshift-config namespace and cluster configuration should assess exposure to potential compromise and prioritize verifying the integrity of the samples-operator pod and its service account.
Why it matters
CVE-2026-107176 allows unauthorized access to all secrets in the openshift-config namespace if the samples-operator pod or its service account token is compromised. Defenders should prioritize verifying the integrity of the samples-operator pod and its service account, assessing exposure to potential compromise, and ensuring that only necessary permissions are granted to the operator.
- Potential unauthorized access to sensitive cluster configuration
- Possible exposure of OAuth identity provider credentials
- Potential exposure of cloud provider credentials
- Compromise of samples-operator pod or service account token could lead to further exploitation
Technical summary
The cluster-samples-operator has a flaw in its RBAC Role coreos-pull-secret-reader, which grants get, list, and watch permissions on all Secret resources in the openshift-config namespace without proper resourceNames scoping. This allows unauthorized access to all secrets in the namespace if the samples-operator pod or its service account token is compromised. The vulnerability could lead to exposure of sensitive cluster configuration, including OAuth identity provider credentials and cloud provider credentials. Defenders should prioritize verifying the integrity of the samples-operator pod and its service account, assessing exposure to potential compromise, and ensuring that only necessary permissions are
Defensive priority
Defenders should prioritize verifying the integrity of the samples-operator pod and its service account, assessing exposure to potential compromise, and ensuring that only necessary permissions are granted to the operator.
Recommended defensive actions
- Verify the integrity of the samples-operator pod and its service account
- Assess exposure to potential compromise
- Ensure that only necessary permissions are granted to the operator
- Review and restrict access to sensitive cluster configuration
- Monitor relevant logs for exposed assets that need extra review
- Track exceptions and retest remediated assets
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected products. However, specific version information and remediation steps are not provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107176 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107176
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107176 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107176
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Cluster-samples-operator: role reads all secrets in openshift-config, not just pull-secret
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107176.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-107176
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.