<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1950087345534883&amp;ev=PageView&amp;noscript=1">
Skip to content

CVE-2026-10090: Red Hat Advanced Cluster Management Privilege Escalation - What It Means for Your Business and How to Respond

Introduction

CVE-2026-10090 is a critical security flaw in Red Hat Advanced Cluster Management for Kubernetes that allows a user with limited namespace permissions to seize full administrative control of the cluster. Organizations running multi-cluster Kubernetes environments that rely on Red Hat’s application deployment features face elevated risk of complete infrastructure compromise. This vulnerability affects businesses across the United States and Canada that depend on container platforms for core operations, from financial services and healthcare to manufacturing and government. Full cluster takeover can disrupt services, expose sensitive data, and trigger regulatory scrutiny under frameworks common in both countries. This post explains why the issue matters to business leaders, outlines practical exposure checks, and provides clear next steps for risk reduction. Technical details appear only in the appendix for security and IT teams.

S1 — Background & History

Red Hat disclosed CVE-2026-10090 on August 5, 2026. The flaw affects the Application Subscription controller inside Red Hat Advanced Cluster Management for Kubernetes, specifically the multicluster-operators-subscription component. Security researcher Christopher Lusk of North Echo Security Research reported the issue. The vulnerability carries a CVSS score of 9.0 and is rated Critical. In plain language, it is a privilege-escalation weakness: a user who holds only ordinary “edit” rights inside a hub namespace can force the controller to apply powerful cluster-wide resources. Key timeline events include public disclosure on August 5, 2026, subsequent Red Hat security advisories (RHSA-2026:60386 and related errata) that shipped fixes for supported ACM 2.x releases, and ongoing vendor guidance recommending migration away from the deprecated Application Subscription model toward GitOps and Argo CD. Environments that never enabled the Application Subscription feature remain unaffected.

S2 — What This Means for Your Business

For business leaders, CVE-2026-10090 converts a routine internal permission into a path to complete control of your Kubernetes clusters. Once an attacker obtains cluster-admin rights, they can shut down or alter production workloads, steal credentials and data stores, and move laterally across managed clusters. Operational disruption can halt customer-facing services, delay product releases, and force costly emergency recovery. Data exposure risks include intellectual property, customer records, and regulated information. Reputation damage follows quickly when outages or breaches become public. Compliance exposure is significant in the United States and Canada: organizations subject to PCI DSS, HIPAA, SOX, PIPEDA, or similar frameworks may face audit findings, fines, or mandatory breach notifications if cluster controls fail. Even without external attackers, a disgruntled or compromised insider with ordinary edit rights can trigger the same outcome. The business impact is therefore both technical and strategic: your container platform, often the backbone of digital operations, becomes a single point of catastrophic failure until the issue is addressed.

S3 — Real-World Examples

Regional Bank Multi-Cluster Outage: A regional bank running Red Hat Advanced Cluster Management across development and production hubs grants developers namespace edit rights for application deployments. An attacker with those rights escalates to cluster-admin, deploys malicious workloads, and disrupts core banking services for several hours. Transaction processing stalls, customer confidence erodes, and regulators open inquiries under U.S. and Canadian banking rules.

Healthcare Provider Data Exposure: A mid-sized hospital system uses ACM to manage clinical application clusters. A contractor with edit privileges in a non-production namespace escalates privileges and accesses patient-data workloads. The incident triggers HIPAA notification obligations in the United States and comparable privacy requirements in Canada, generating legal costs and potential class-action exposure.

Manufacturing Firm Supply-Chain Halt: A large manufacturer relies on ACM-managed clusters for production-line orchestration and inventory systems. Privilege escalation allows an insider to alter cluster configurations, stopping automated manufacturing processes. The resulting downtime cascades into delayed shipments and contractual penalties with North American suppliers and customers.

Government Agency Service Interruption: A provincial or state agency manages citizen-facing applications on ACM hubs. Limited-privilege staff escalate to full control and disrupt online services. Public trust declines, media coverage intensifies, and internal audits expand across multiple agencies.

S4 — Am I Affected?

  • You are running Red Hat Advanced Cluster Management for Kubernetes version 2.11, 2.13, 2.14, 2.15, 2.16, 2.17, or other 2.x releases that still use the Application Subscription model.
  • Your environment contains the multicluster-operators-subscription controller and users hold namespace-scoped “edit” privileges in ACM hub namespaces.
  • You have not applied the Red Hat security updates released under RHSA-2026:60386 and related advisories.
  • You have not removed the aggregating ClusterRole that grants subscription management rights to the Kubernetes edit role.
  • You continue to use Application Subscriptions rather than the recommended GitOps Operator or Argo CD model.
  • You have not audited who can create Channel and Subscription resources in hub namespaces.

If any of the above statements apply, treat the environment as exposed until verified otherwise.

Key Takeaways

  • CVE-2026-10090 allows limited users to gain full cluster-admin control in Red Hat Advanced Cluster Management environments that still use Application Subscriptions.
  • Business consequences include operational outages, data exposure, regulatory penalties, and reputational harm across U.S. and Canadian organizations.
  • Immediate checks of ACM versions, user privileges, and subscription usage determine exposure.
  • Vendor patches and the removal of the aggregating ClusterRole form the primary short-term defenses.
  • Long-term risk reduction requires migration to GitOps-based application management and continuous privilege reviews.

Call to Action

Contact IntegSec today to schedule a focused penetration test of your Kubernetes and multi-cluster environment. Our team identifies privilege-escalation paths, validates patch effectiveness, and delivers actionable remediation guidance that reduces real-world risk. Visit https://integsec.com to begin the conversation and strengthen your security posture with confidence.

TECHNICAL APPENDIX (security engineers, pentesters, IT professionals only)

A — Technical Analysis

The root cause is insufficient authorization checking inside the Application Subscription controller (multicluster-operators-subscription). A user possessing only namespace-scoped edit privileges can create a Channel resource that points to an attacker-controlled Helm repository and a Subscription resource that references it. The controller then fetches and applies the chart contents using its own elevated service-account privileges. It neither verifies that the creator holds the open-cluster-management:subscription-admin role nor confines applied resources to the subscription’s namespace. Consequently, the chart can contain cluster-scoped objects such as a ClusterRoleBinding that grants the attacker’s ServiceAccount the cluster-admin ClusterRole. Attack vector is network (within the cluster API), complexity is low, privileges required are high (namespace edit), user interaction is none, and scope is changed. The CVSS v3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L. The weakness is classified as CWE-267 (Privilege Defined With Unsafe Actions). Official references include the Red Hat CVE page and associated RHSA advisories.

B — Detection & Verification

Version enumeration can be performed with oc get csv -n open-cluster-management or by inspecting the multicluster-operators-subscription image tags against Red Hat’s fixed package versions. Scanner signatures should flag the presence of the vulnerable multicluster-operators-subscription package and the existence of the ClusterRole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit. Log indicators include unexpected creation of Channel or Subscription resources by non-subscription-admin users and subsequent application of cluster-scoped objects. Behavioral anomalies appear as sudden ClusterRoleBinding creations granting cluster-admin rights shortly after Subscription reconciliation. Network exploitation indicators are limited to internal API traffic; external network signatures are not applicable because the attack occurs through legitimate cluster API calls.

C — Mitigation & Remediation

  1. Immediate (0–24h): Delete the aggregating ClusterRole with oc delete clusterrole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit. Verify with oc auth can-i create subscriptions.apps.open-cluster-management.io --as=<user> -n <namespace> (expected result: no). Restrict edit privileges in hub namespaces to trusted personnel only.
  2. Short-term (1–7d): Apply the official Red Hat patches from RHSA-2026:60386 and related advisories for the installed ACM 2.x stream. Re-apply the ClusterRole deletion after any operator restart or MultiClusterHub reconciliation until the fixed release is confirmed. Audit all existing Channel and Subscription resources for untrusted Helm repositories.
  3. Long-term (ongoing): Migrate fully to the GitOps Operator / Argo CD application model as recommended by Red Hat. Remove Application Subscription usage entirely. Implement continuous RBAC reviews, least-privilege enforcement, and monitoring of cluster-scoped resource creation. Environments that never used Application Subscriptions require no further action beyond confirmation.

D — Best Practices

  • Enforce least-privilege RBAC so that namespace edit rights never automatically convey the ability to manage Application Subscriptions.
  • Prefer GitOps and Argo CD over the deprecated Application Subscription model for all multi-cluster deployments.
  • Continuously monitor for creation of ClusterRoleBindings and other cluster-scoped objects originating from subscription controllers.
  • Maintain an up-to-date inventory of ACM operator versions and apply vendor security errata promptly.
  • Periodically validate that non-subscription-admin users cannot create Channel or Subscription resources in hub namespaces

Leave Comment

Want to strengthen your security posture?

Want to strengthen your organization’s security? Explore our blog insights and contact our team for expert guidance tailored to your needs.