rhacm2/multicluster-operators-subscription-rhel9 vulnerabilities
CVEs whose affected-version data names the rhacm2/multicluster-operators-subscription-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-66792Critical· 9.9A flaw was found in the multicloud-operators-subscription component
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…
CVE-2026-10090Critical· 9.0A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM)
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can cre…
CVE-2025-7195Medium· 6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…