CVE-2026-72508
🟠 Łataj w tym tygodniu
Błąd w Red Hat Advanced Cluster Management pozwala na eskalację uprawnień przez atak z wykorzystaniem ServiceAccount.
CVSS
9.9
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
privilege-escalation rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-08-12 20:17:49 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-14 19:07:46 UTC |
Referencje
- https://access.redhat.com/security/cve/CVE-2026-72508 (secalert@redhat.com)
- https://bugzilla.redhat.com/show_bug.cgi?id=2514225 (secalert@redhat.com)