multicloud-operators-subscription Vulnerability: Critical CVE-2026-67567
- Severity
- CRITICAL
- CVSS
- 9.9
- Affected component
- multicloud-operators-subscription (npm)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the multicloud-operators-subscription component. This flaw allows tenants to bypass security controls and deploy arbitrary resources across the entire cluster.
What happened
A flaw has been discovered in the multicloud-operators-subscription component, identified as CVE-2026-67567. This vulnerability permits tenants with the ability to create HelmRelease custom resources (CRs) to bypass existing security controls. The HelmRelease controller processes Helm chart templates using elevated ServiceAccount privileges without proper validation, enabling the deployment of arbitrary resources across the entire cluster. This poses a significant security risk.
The vulnerability was first flagged on August 20, 2026. It has a CVSS score of 9.9, indicating a critical severity level. The flaw has not yet been exploited in the wild, and no supply-chain attack has been reported. However, the potential impact is severe, necessitating immediate attention and action.
What to do about it
- Monitor the primary sources for updates on a fixed version of multicloud-operators-subscription.
- Review your HelmRelease custom resources for any unauthorized deployments.
- No official fix has been published yet. Stay informed by consulting the sources below for updates.
How 0Day would have caught this
multicloud-operators-subscription is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using the multicloud-operators-subscription component. Consult the primary sources for more detailed information.
What should I do right now?
Monitor the primary sources for updates on a fixed version and review your HelmRelease custom resources for unauthorized deployments.
Has a fix been released?
No official fix has been published yet. Continue to monitor the sources for updates.