NPM · AUGUST 2026 · EARLY WARNING

multicloud-operators-subscription Vulnerability: Critical CVE-2026-67567

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.9
Affected component
multicloud-operators-subscription (npm)
Patched version
Not yet available
CVE-2026-67567

An early warning has been issued for a critical vulnerability in the multicloud-operators-subscription component. This flaw allows tenants to bypass security controls and deploy arbitrary resources across the entire cluster.

What happened

A flaw has been discovered in the multicloud-operators-subscription component, identified as CVE-2026-67567. This vulnerability permits tenants with the ability to create HelmRelease custom resources (CRs) to bypass existing security controls. The HelmRelease controller processes Helm chart templates using elevated ServiceAccount privileges without proper validation, enabling the deployment of arbitrary resources across the entire cluster. This poses a significant security risk.

The vulnerability was first flagged on August 20, 2026. It has a CVSS score of 9.9, indicating a critical severity level. The flaw has not yet been exploited in the wild, and no supply-chain attack has been reported. However, the potential impact is severe, necessitating immediate attention and action.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If multicloud-operators-subscription is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using the multicloud-operators-subscription component. Consult the primary sources for more detailed information.

What should I do right now?

Monitor the primary sources for updates on a fixed version and review your HelmRelease custom resources for unauthorized deployments.

Has a fix been released?

No official fix has been published yet. Continue to monitor the sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats