Red HatCVE-2026-75924
Red Hat Multicluster Engine for Kubernetes: information disclosure
High8.7CVE-2026-75924 · Published Aug 18, 2026 · updated Aug 20, 2026
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Multicluster Engine for Kubernetes Product | all versions | No fix yet |
| Red Hat Advanced Cluster Management for Kubernetes 2 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | A flaw was found in the legacy client-initiated account-linking endpoint of... | High7.3 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: secrets in logs | Medium6.5 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure | Medium5.4 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management: improper privilege management | Medium5.8 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: code execution | Medium4.4 | No fix yet |
| Aug 18 | reset-credentials flow of the keycloak-services: weak password recovery | Critical9.1 | No fix yet |