Red HatCVE-2026-72508
Red Hat multicloud-operators-subscription: privilege escalation
Critical9.9CVE-2026-72508 · Published Aug 12, 2026 · updated Aug 27, 2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-250
- www.cve.org/CVERecord?id=CVE-2026-72508
- nvd.nist.gov/vuln/detail/CVE-2026-72508
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/security/cve/CVE-2026-72508
- bugzilla.redhat.com/show_bug.cgi?id=2514225
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Red Hat: mass assignment | High8.5 | No fix yet |
| Aug 12 | Red Hat insights-client. The: excessive privileges | Medium6.5 | No fix yet |
| Aug 12 | Red Hat search-v2-api: denial of service | High7.5 | No fix yet |
| Aug 12 | Red Hat acm-search-v2-rhel9: remote code execution | Critical9.0 | No fix yet |
| Aug 12 | Red Hat open-iscsi. This vulnerability: denial of service | Medium6.5 | No fix yet |
| Aug 12 | Red Hat open-iscsi: integer overflow | Medium6.5 | No fix yet |