CVE-2026-93017High· 7.7▾ TwilightThe `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The insights-operator-gather ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.
- apiGroups:
- ""
resources:
- secrets
verbs:
- get
- list
By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.
spec:
serviceAccountName:"gather"
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1442Medium· 6.0grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)
CVE-2026-107623Medium· 4.3A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak
CVE-2026-107604Medium· 4.9A flaw was found in the installation provider and client registration endpoints of the Keycloak identity management service
CVE-2026-107565Medium· 5.1A flaw was found in luksmeta
CVE-2026-107466Medium· 6.1A flaw was found in flatpak-builder
CVE-2026-107445Medium· 5.4A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier