{"id":"CVE-2026-66792","title":"A flaw was found in the multicloud-operators-subscription component","summary":"A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"Red Hat","product":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","affected":["multicluster-globalhub/multicluster-globalhub-agent-rhel9 (all versions)","multicluster-globalhub/multicluster-globalhub-manager-rhel9 (all versions)","multicluster-globalhub/multicluster-globalhub-rhel9-operator (all versions)","rhacm2/multicluster-operators-application-rhel9 (all versions)","rhacm2/multicluster-operators-subscription-rhel9 (all versions)","rhacm2/multicluster-operators-application-rhel9 (all versions)","rhacm2/multicluster-operators-subscription-rhel9 (all versions)","rhacm2/multicluster-operators-application-rhel9 (all versions)","rhacm2/multicluster-operators-subscription-rhel9 (all versions)","rhacm2/multicluster-operators-application-rhel9 (all versions)","rhacm2/multicluster-operators-subscription-rhel9 (all versions)","rhacm2/multicluster-operators-application-rhel9 (all versions)","rhacm2/multicluster-operators-subscription-rhel9 (all versions)","rhacm2/multicluster-operators-application-rhel9 (all versions)","rhacm2/multicluster-operators-subscription-rhel9 (all versions)","rhacm2/acm-governance-policy-framework-addon-rhel9","rhacm2/cert-policy-controller-rhel9","rhacm2/config-policy-controller-rhel9","rhacm2/governance-policy-propagator-rhel9","rhacm2/search-collector-rhel9","openshift4/cnf-tests-rhel8 (all versions)","openshift4/lifecycle-agent-operator-bundle","openshift4/lifecycle-agent-rhel9-operator","openshift4/topology-aware-lifecycle-manager-aztp-rhel9","openshift4/topology-aware-lifecycle-manager-recovery-rhel8","openshift4/topology-aware-lifecycle-manager-recovery-rhel9","openshift4/topology-aware-lifecycle-manager-rhel8-operator","openshift4/topology-aware-lifecycle-manager-rhel9-operator","openshift4/ztp-site-generate-rhel8 (all versions)","odf4/odf-cli-rhel9","odf4/odf-multicluster-rhel9-operator","odf4/odr-rhel9-operator"],"published":"2026-08-17","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:17:11.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66792","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:60386","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60387","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60388","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60389","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60390","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60391","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:67516","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-66792","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507537","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66792.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-66792"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66792"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-18T14:53:42.904208Z"},"epss":0.00435,"epssPercentile":0.37149,"ingestedAt":"2026-09-21T11:35:54.429Z","patched":["multicluster_global_hub 1.4.9","advanced_cluster_management_for_kubernetes 2.11","advanced_cluster_management_for_kubernetes 2.13","advanced_cluster_management_for_kubernetes 2.14","advanced_cluster_management_for_kubernetes 2.15","advanced_cluster_management_for_kubernetes 2.16","advanced_cluster_management_for_kubernetes 2.17"],"slug":"CVE-2026-66792","body":"## Overview\n\nA flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)\n- **RHSA-2026:60387** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.11 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60387)\n- **RHSA-2026:60390** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60390)\n- **RHSA-2026:60388** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60388)\n- **RHSA-2026:60389** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60389)\n- **RHSA-2026:60391** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60391)\n- **RHSA-2026:60386** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60386)\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66792.json)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":54.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}