Red Hat Advanced Cluster Management for Kubernetes 2 is affected by CVE-2026-10090, an Important privilege escalation flaw in the multicluster-operators-subscription component that can let a user with namespace-scoped edit rights gain full cluster-admin access. Red Hat assigned the issue a CVSS v3.1 score of 9.9, and the Canadian Centre for Cyber Security issued advisory AV26-803 urging organizations to review Red Hat guidance and apply updates when available.
According to Red Hat's bug report and CVE record, the Application Subscription controller can be abused by creating a malicious Channel and Subscription that point to an attacker-controlled Helm repository. The controller then applies the Helm chart with elevated privileges without verifying the creator holds the required open-cluster-management:subscription-admin role and without restricting deployed resources to the subscription namespace, allowing deployment of cluster-scoped objects such as a ClusterRoleBinding that grants the attacker's ServiceAccount the cluster-admin ClusterRole. Red Hat said no mitigation meeting its product security criteria is currently available, and credited Christopher Lusk of North Echo Security Research with reporting the flaw.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-803 warning that Red Hat Advanced Cluster Management for Kubernetes 2 is affected by CVE-2026-10090. The notice directed users and administrators to review Red Hat guidance and apply security updates when available.
Red Hat published CVE-2026-10090 as an Important privilege escalation vulnerability affecting Red Hat Advanced Cluster Management for Kubernetes 2 and the rhacm2/multicluster-operators-subscription-rhel9 component. Red Hat assigned a CVSS 9.9 score, said no qualifying mitigation was available, and credited Christopher Lusk of North Echo Security Research for reporting the issue.
Red Hat recorded Bugzilla issue 2483292 for a privilege escalation flaw in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes, specifically multicluster-operators-subscription. The issue describes how a namespace-scoped edit user could deploy a cluster-scoped ClusterRoleBinding via a malicious Channel and Subscription to gain cluster-admin privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.