CVE-2026-10090 Details
Description
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the "open-cluster-management:subscription-admin" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the "cluster-admin" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.
A privilege escalation vulnerability exists in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes (ACM) version 2. A user with namespace-scoped 'edit' privileges in an ACM hub namespace can exploit this flaw by creating a Channel resource that points to a Helm repository they control, along with a Subscription resource that references it. The app-subscription controller then fetches and applies the contents of the Helm chart using elevated permissions, without verifying if the user has the 'open-cluster-management:subscription-admin' role or restricting the applied resources to the subscription namespace. This oversight allows the inclusion of cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding that grants the user's ServiceAccount the 'cluster-admin' role. Exploiting this vulnerability leads to unauthorized privilege escalation to cluster-admin, contradicting ACM's documentation that states non-subscription-admin users should only have resources deployed in their subscription namespace.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-267 | Privilege Defined With Unsafe Actions | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | [email protected] |
| Sep 8, 2026 | CVE Modified | [email protected] |
| Sep 5, 2026 | CVE Modified | [email protected] |
| Sep 5, 2026 | CVE Modified | [email protected] |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |