CVE-2026-10090 is a privilege escalation vulnerability in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM) 2. A user with namespace-scoped edit privileges in an ACM hub namespace can create a Channel resource that points to an attacker-controlled Helm repository and a Subscription resource that references it. The controller then fetches and applies the Helm chart contents using its own elevated authority. The flaw exists because the controller does not verify that the subscription creator holds the required open-cluster-management:subscription-admin role and does not constrain deployed resources to the subscription namespace. As a result, an attacker can cause cluster-scoped Kubernetes resources to be created, including RBAC objects that elevate the attacker to cluster-admin. The issue breaks the intended tenant and namespace boundary enforced by ACM for non-subscription-admin users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A privilege escalation vulnerability in the Application Subscription controller of Red Hat Advanced Cluster Management for Kubernetes that allows a low-privileged user to deploy attacker-controlled Helm chart content with elevated controller authority and gain full cluster-admin privileges.
A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) Application Subscription controller that allows a user with namespace-scoped edit privileges to deploy cluster-scoped resources and escalate to full cluster-admin access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.