RED Hat has identified a critical privilege escalation vulnerability in its Advanced Cluster Management (ACM) for Kubernetes, tracked as CVE-2026-10090, which has a CVSS score of 9.9. This flaw allows users with namespace edit rights to gain full cluster-admin access by deploying cluster-scoped resources via a Helm chart. The issue lies in the Application Subscription controller, which does not properly verify roles and permissions.
Although no public exploits have yet been confirmed, it is advised to limit namespace edit rights and audit existing subscriptions until a patch is implemented.