PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93017 Red Hat CVE debrief

CVE-2026-93017 Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and cluster-reader. The insights-operator-gather ClusterRole grants the operator's service account read access to all secrets in the cluster, allowing an attacker to access any secret in any namespace by spawning a pod with the gather service account mounted. Cluster administrators and security teams responsible for OpenShift Container Platform 4 deployments should assess exposure and verify the gather service account's access to secrets. This access could be used to gather sensitive information.

Vendor
Red Hat
Product
Red Hat OpenShift Container Platform 4
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Cluster administrators and security teams responsible for OpenShift Container Platform 4 deployments should assess exposure and verify the gather service account's access to secrets.

Why it matters

CVE-2026-93017 allows an attacker to access any secret in any namespace in the cluster, potentially leading to sensitive information disclosure. Cluster administrators and security teams should assess exposure, verify the gather service account's access, and implement compensating controls to detect and prevent exploitation.

  • An attacker could access sensitive information stored in secrets across the cluster.
  • Cluster administrators must verify and limit the gather service account's access to secrets to prevent unauthorized information disclosure.
  • Defenders should monitor the cluster for unusual secret access patterns to detect potential exploitation.

Technical summary

The insights-operator-gather ClusterRole grants the operator's service account read access to all secrets in the cluster, allowing an attacker to access any secret in any namespace by spawning a pod with the gather service account mounted. This access could be used to gather sensitive information. Cluster administrators and security teams should assess exposure, verify the gather service account's access, and implement compensating controls to detect and prevent exploitation. The CVE record and source item indicate that the insights-operator-gather ClusterRole allows read access to all secrets in the cluster.

Defensive priority

Operators should verify and limit the gather service account's access to secrets.

Recommended defensive actions

  • Verify the gather service account's access to secrets and limit it to the minimum required.
  • Monitor the cluster for unusual secret access patterns.
  • Implement compensating controls to detect and prevent sensitive information disclosure.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item indicate that the insights-operator-gather ClusterRole allows read access to all secrets in the cluster. This access could be used to gather sensitive information. The insights-operator-gather ClusterRole grants the operator's service account read access to all secrets in the cluster. Cluster administrators and security teams should assess exposure, verify the gather service account's access, and implement compensating controls to detect and prevent exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93017 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93017

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93017 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93017

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.