Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)
This critical-severity Red Hat Linux advisory covers CVE-2026-72508 affecting Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA).
This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster. The application-manager addon's ServiceAccount is granted broad wildcard permissions by default, enabling a malicious tenant to deploy arbitrary cluster-scoped resources.
This significantly increases the blast radius beyond typical namespace boundaries. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Weakness: CWE-250.
Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 23 days ago·verify at source
- rhacm2/multicluster-operators-subscription-rhel9:1787263584
- rhacm2/multicluster-operators-subscription-rhel9:1787263693
- rhacm2/multicluster-operators-subscription-rhel9:1787170830
- rhacm2/multicluster-operators-subscription-rhel9:1787240030
- rhacm2/multicluster-operators-subscription-rhel9:1787242321
- rhacm2/multicluster-operators-subscription-rhel9:1787242108
- RHSA-2026:60387
- RHSA-2026:60390
- RHSA-2026:60388
- RHSA-2026:60389
- RHSA-2026:60391
- RHSA-2026:60386
Official advisory · high-confidence parse· fetched 23 days ago·verify at source
Mitigation checklist
- To mitigate this issue, Red Hat Advanced Cluster Management for Kubernetes administrators should configure the application-manager addon to use the least-privilege RBAC variant. This involves applying the addon/manifests/permission/role.yaml configuration, which restricts the permissions granted to the application-manager ServiceAccount. Consult Red Hat documentation for specific instructions on how to apply custom RBAC configurations for RHACM addons. Applying this change may require a restart or reload of the affected components to take effect.
Official advisory · high-confidence parse· fetched 23 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.