securityonline.info 8/10/2026, 3:11:23 PM · external

Red Hat ACM Flaw (CVE-2026-10090) Lets Users Gain Cluster Admin

Red Hat ACM Flaw (CVE-2026-10090) Lets Users Gain Cluster Admin
CyberSIXT Evidence Panel
Primary Source access.redhat.com
CISA KEV Not in KEV
Patch Patch Status Unknown

RED Hat has identified a critical privilege escalation vulnerability in its Advanced Cluster Management (ACM) for Kubernetes, tracked as CVE-2026-10090, which has a CVSS score of 9.9. This flaw allows users with namespace edit rights to gain full cluster-admin access by deploying cluster-scoped resources via a Helm chart. The issue lies in the Application Subscription controller, which does not properly verify roles and permissions.

Although no public exploits have yet been confirmed, it is advised to limit namespace edit rights and audit existing subscriptions until a patch is implemented.

View Primary Source Via securityonline.info

Article by CyberSIXT