Red Hat Advanced Cluster Management for Kubernetes Privilege Escalation Threat
An early warning has been issued regarding a critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes that may allow users with limited privileges to escalate to full cluster-admin privileges.
What happened
Reportedly, a flaw in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes (tracked as CVE-2026-10090) allows users with limited privileges to escalate to full cluster-admin privileges. This appears to be due to the controller applying Helm chart contents without proper verification or restriction. The vulnerability is under investigation and has been assigned a CVSS score of 9.9, indicating a critical severity level.
Affected components include the multicluster-operators-subscription (kubernetes). It is recommended to upgrade to the latest version of Red Hat Advanced Cluster Management for Kubernetes and review current deployments for any unauthorized cluster-admin privileges. For more detailed information, primary sources should be consulted.
How 0Day mitigates this
multicluster-operators-subscription is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.