PatchSiren cyber security CVE debrief
CVE-2026-93017 Red Hat CVE debrief
CVE-2026-93017 Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and cluster-reader. The insights-operator-gather ClusterRole grants the operator's service account read access to all secrets in the cluster, allowing an attacker to access any secret in any namespace by spawning a pod with the gather service account mounted. Cluster administrators and security teams responsible for OpenShift Container Platform 4 deployments should assess exposure and verify the gather service account's access to secrets. This access could be used to gather sensitive information.
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Cluster administrators and security teams responsible for OpenShift Container Platform 4 deployments should assess exposure and verify the gather service account's access to secrets.
Why it matters
CVE-2026-93017 allows an attacker to access any secret in any namespace in the cluster, potentially leading to sensitive information disclosure. Cluster administrators and security teams should assess exposure, verify the gather service account's access, and implement compensating controls to detect and prevent exploitation.
- An attacker could access sensitive information stored in secrets across the cluster.
- Cluster administrators must verify and limit the gather service account's access to secrets to prevent unauthorized information disclosure.
- Defenders should monitor the cluster for unusual secret access patterns to detect potential exploitation.
Technical summary
The insights-operator-gather ClusterRole grants the operator's service account read access to all secrets in the cluster, allowing an attacker to access any secret in any namespace by spawning a pod with the gather service account mounted. This access could be used to gather sensitive information. Cluster administrators and security teams should assess exposure, verify the gather service account's access, and implement compensating controls to detect and prevent exploitation. The CVE record and source item indicate that the insights-operator-gather ClusterRole allows read access to all secrets in the cluster.
Defensive priority
Operators should verify and limit the gather service account's access to secrets.
Recommended defensive actions
- Verify the gather service account's access to secrets and limit it to the minimum required.
- Monitor the cluster for unusual secret access patterns.
- Implement compensating controls to detect and prevent sensitive information disclosure.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item indicate that the insights-operator-gather ClusterRole allows read access to all secrets in the cluster. This access could be used to gather sensitive information. The insights-operator-gather ClusterRole grants the operator's service account read access to all secrets in the cluster. Cluster administrators and security teams should assess exposure, verify the gather service account's access, and implement compensating controls to detect and prevent exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93017 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93017
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93017 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93017
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and clust
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93017.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-93017
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.