---
id: CVE-2026-66792
title: A flaw was found in the multicloud-operators-subscription component
summary: >-
  A flaw was found in the multicloud-operators-subscription component. This
  vulnerability allows a user on a managed cluster to escalate their privileges
  by creating a Subscription with specific, crafted annotations. Successful
  exploitatio…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: Red Hat
product: multicluster-globalhub/multicluster-globalhub-agent-rhel9
affected:
  - multicluster-globalhub/multicluster-globalhub-agent-rhel9 (all versions)
  - multicluster-globalhub/multicluster-globalhub-manager-rhel9 (all versions)
  - multicluster-globalhub/multicluster-globalhub-rhel9-operator (all versions)
  - rhacm2/multicluster-operators-application-rhel9 (all versions)
  - rhacm2/multicluster-operators-subscription-rhel9 (all versions)
  - rhacm2/multicluster-operators-application-rhel9 (all versions)
  - rhacm2/multicluster-operators-subscription-rhel9 (all versions)
  - rhacm2/multicluster-operators-application-rhel9 (all versions)
  - rhacm2/multicluster-operators-subscription-rhel9 (all versions)
  - rhacm2/multicluster-operators-application-rhel9 (all versions)
  - rhacm2/multicluster-operators-subscription-rhel9 (all versions)
  - rhacm2/multicluster-operators-application-rhel9 (all versions)
  - rhacm2/multicluster-operators-subscription-rhel9 (all versions)
  - rhacm2/multicluster-operators-application-rhel9 (all versions)
  - rhacm2/multicluster-operators-subscription-rhel9 (all versions)
  - rhacm2/acm-governance-policy-framework-addon-rhel9
  - rhacm2/cert-policy-controller-rhel9
  - rhacm2/config-policy-controller-rhel9
  - rhacm2/governance-policy-propagator-rhel9
  - rhacm2/search-collector-rhel9
  - openshift4/cnf-tests-rhel8 (all versions)
  - openshift4/lifecycle-agent-operator-bundle
  - openshift4/lifecycle-agent-rhel9-operator
  - openshift4/topology-aware-lifecycle-manager-aztp-rhel9
  - openshift4/topology-aware-lifecycle-manager-recovery-rhel8
  - openshift4/topology-aware-lifecycle-manager-recovery-rhel9
  - openshift4/topology-aware-lifecycle-manager-rhel8-operator
  - openshift4/topology-aware-lifecycle-manager-rhel9-operator
  - openshift4/ztp-site-generate-rhel8 (all versions)
  - odf4/odf-cli-rhel9
  - odf4/odf-multicluster-rhel9-operator
  - odf4/odr-rhel9-operator
patched:
  - multicluster_global_hub 1.4.9
  - advanced_cluster_management_for_kubernetes 2.11
  - advanced_cluster_management_for_kubernetes 2.13
  - advanced_cluster_management_for_kubernetes 2.14
  - advanced_cluster_management_for_kubernetes 2.15
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_management_for_kubernetes 2.17
published: '2026-08-17'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T17:17:05.663'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66792'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:60386'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60387'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60388'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60389'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60390'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60391'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:67516'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71597'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-66792'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507537'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66792.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-66792'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66792'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00494
epssPercentile: 0.41516
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-18T14:53:42.904208Z'
ingestedAt: '2026-09-21T11:35:54.429Z'
---

## Overview

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)
- **RHSA-2026:60387** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.11 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60387)
- **RHSA-2026:60390** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60390)
- **RHSA-2026:60388** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60388)
- **RHSA-2026:60389** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60389)
- **RHSA-2026:60391** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60391)
- **RHSA-2026:60386** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60386)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-66792.json)
