RHSA-2026:60389HighCVSS 9.9

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.6 security update

Published
August 26, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (41)

📋 Description

CVE-2026-10090 — multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-18874 — volsync-addon-controller: volsync-addon-controller: annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-55677 — github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-64927 — multicloud-operators-channel: multicloud-operators-channel: cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy CVE-2026-66780 — submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace CVE-2026-66781 — submariner-operator: submariner-operator: IPsec PSK stored cleartext in Submariner CR spec CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters CVE-2026-66793 — governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke CVE-2026-66797 — cluster-backup-operator: cluster-backup-operator: Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin CVE-2026-66798 — cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods CVE-2026-66799 — cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement CVE-2026-66800 — cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66878 — multicloud-operators-subscription: multicloud-operators-subscription: FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration CVE-2026-67567 — multicloud-operators-subscription: multicloud-operators-subscription: HelmRelease chart applied with controller SA without GVK or namespace restriction CVE-2026-70398 — multicloud-integrations: multicloud-integrations: GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace CVE-2026-70495 — search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters CVE-2026-70496 — search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork CVE-2026-71468 — acm-search-v2-api-rhel9: search-v2-api: Cross-user bearer-token reuse via global federation-config cache CVE-2026-71469 — acm-search-v2-api-rhel9: search-v2-api: Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS CVE-2026-71470 — acm-search-v2-rhel9: search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA CVE-2026-71471 — acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image CVE-2026-71472 — acm-search-v2-rhel9: search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM CVE-2026-71473 — acm-search-v2-rhel9: search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke CVE-2026-71474 — insights-client-rhel9: insights-client: Pull-secret bearer token written to logs on non-200 CCX response CVE-2026-71475 — insights-client-rhel9: insights-client: Spoke-controlled ClusterID injected unencoded into Insights API URL path CVE-2026-71845 — insights-client: insights-client: CCX_TOKEN bearer credential logged in clear text at startup via setDefault() CVE-2026-71846 — insights-client: insights-client: ClusterRole grants cluster-wide secrets get/list/watch beyond least privilege CVE-2026-72508 — multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ServiceAccounts bound to wildcard RBAC (//*) CVE-2026-72526 — multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation CVE-2026-73122 — multicloud-operators-channel: multicloud-operators-channel: auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces CVE-2026-73137 — multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace CVE-2026-73834 — must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction CVE-2026-75485 — must-gather: must-gather: cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials CVE-2026-76827 — search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)

🎯 Affected products185

  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:2fbdcd7ec8b4bf9b8a676f67b50f78a3766e47f50fc2c681cf1088246124fc63_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:a0de2f3f7fcfdaf07964bac6c670964df0fc62673fbe302f2aae0133438a9a96_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:d5cea514bb9ffb3d92d61c901be6d19f9816e58f8ec7e44c37087da82ac4c3a3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:dfcde33745038fbb8d34f24fab283b47d73a47ccc53b5cd0dce512663265907e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:84b5b40c19ccca7699c82f47673c8bdd705b0ec25c55035b6b7a13b056b6ae55_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:9d22731adc0bd2f259c8f5351ecb06d46181922e36e21c7f27607cf69fb9e499_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:bf594cfd20b4b134bc550381b096b5b19c2ef8c41cca797351c7800fe72e2590_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:c6ea9fe6b904ec00f06f4f791516179cbfb25dff63a21f0d2cae4e164274d6e0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:0b7d15a77efc47fb2bc6a9d6f259847607db76052afad1ebb6f3426bc2adb717_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:0e4b736a5947d7831f1a070909e7cdb27502cfae90f04b03068826486a3eaed9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2fa9a6fbc5dfa7c6f37c42ecf17d2510dd1c01b4376c79951b5ae5499c30b828_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:be0871d3c4e2596842eaca587e2e0c591f0738531dd0eb0536f5b364ef02b106_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:3d47ddc0be3ac9717facf3d1244fb350971a5de0f87352e7c42573b827bbb25a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:68f526388c40361b83d439a7e76c10ef936f79d8c4db628449537cee531b3d3f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:b56f7236ee77eeb6857b5155b84d6456858d84209e2077bedb6c1351cd3a159d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d31dede2c4178056e27f43fc15f29a52b22bc0b7fc9adb7e42fea1dcbc747f83_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:42da7c725a91592cb71d628ac008ce8c8ffe3a13b17dba67f742e97754933268_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:7c64e9e4e73000b43def1792c2191ff036814a250c688d76e7ae7dae5f2aa7c2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9f348075b4013cc5ef3f6753399e76a10f7c24149e75012f6c5bd70057e20247_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:c58d83ea820fbd86698b003ca52f7705d9f7e96339a2e2d32affd7b60dfdd4f2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:157cbbec2bc7212d4367368d741aeac19bf60f05562733875a2188ffa573cc80_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:2f69c79e9818c9e6c08585ed9ae6e5e2527b34d354bd0e5e26cdf3d38e80ba64_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:8cd300326acbc48af765481eff83304b659431ad8598f729bb607d967753e124_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:a175a8a105c62e679044a65a9d89f640d44b2a2894231b37f9c7d2f60af89bdf_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:35fd593bcbeb209edd5c8f342d863f4e6661467f2427b42df882400d576dbdb7_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:71b09f020a8e1ee6b9ec9c53900a1c6d13207b581c4ac5e09b043dda46d975a9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:b541cb5fa00a4ed2b00aa34b78c48b926c4dae6131f3cd5479b3c71acb1452bc_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ec99abc6fbdf26383493cd32e05a152f480ce9a1bb0e9c5faae44df3946f1f77_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:265c21858030f519f36042c109355c4cd6898e73759d96a9170e5cfd0828ab23_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • +155 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Remove the RBAC aggregation (immediate, targeted) Delete the ClusterRole that aggregates Application Subscription management permissions into the Kubernetes edit role: oc delete clusterrole open-cluster-management:multicloud-operators-subscription:rbac-aggregate-edit Verification: oc auth can-i create subscriptions.apps.open-cluster-management.io --as=<user> -n <namespace> Expected result after mitigation: no Important notes: This ClusterRole is recreated by the multiclusterhub-operator during reconciliation. Customers must re-apply this mitigation after any ACM operator upgrade, operator pod restart, or MultiClusterHub CR modification until a fixed release is installed. After deletion, users with only the edit or view roles will no longer be able to create or delete Application Subscription, Channel, or related resources. Users who are bound to open-cluster-management:subscription-admin or who have explicit RBAC grants are unaffected. Existing Application Subscriptions continue to function normally. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: To mitigate this vulnerability, ensure that the `volsync-addon-deploy-type` annotation is not explicitly set to `olm`. The default Helm deployment type for volsync-addon-controller in Red Hat Advanced Cluster Management for Kubernetes (since ACM 2.13) is not affected by this flaw. Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict the creation of `Channel` resources to trusted administrators within Red Hat Advanced Cluster Management. This limits the attack surface by preventing unauthorized tenants from exploiting the confused deputy vulnerability in the `multicloud-operators-channel` component. Workaround: To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK. Workaround: To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist. Workaround: Restrict access to the backup storage location (e.g., S3 bucket) to authorized personnel only. Implement strict Role-Based Access Control (RBAC) to limit which users or service accounts can create Velero Backup objects within the open-cluster-management-backup namespace. This prevents an attacker from injecting malicious ClusterRoleBindings into backups or referencing untrusted backup objects. Ensure that only trusted and verified backups are used for restore operations. Workaround: To mitigate this issue, ensure that only highly trusted administrators are granted `namespace-admin` privileges within the `open-cluster-management-backup` namespace. This restricts the ability to create or modify `Restore` Custom Resources with malicious hooks, thereby preventing arbitrary command execution in restored pods. Workaround: To mitigate this issue, restrict administrative access to the `open-cluster-management-backup` namespace. Only trusted administrators should have permissions to create or modify `Restore` Custom Resources within this namespace, as this action is required to exploit the vulnerability. Workaround: To mitigate this issue, restrict the ability of untrusted tenants to create `HelmRelease` custom resources within the cluster. Implement strict Role-Based Access Control (RBAC) policies to limit which users or service accounts can create or modify `HelmRelease` objects. This will prevent unauthorized users from leveraging the controller's elevated privileges for cluster-wide resource deployment. Workaround: To mitigate this issue, ensure that the `FEATURE_FEDERATED_SEARCH` is not enabled if federated search functionality is not required. This feature is disabled by default in Red Hat Advanced Cluster Management for Kubernetes. If `FEATURE_FEDERATED_SEARCH` is enabled, consider disabling it to prevent unauthorized cross-user data access. Disabling this feature will impact the ability to perform federated searches across managed hubs. Workaround: To mitigate this issue, restrict network access to the `search-v2-api` component within Red Hat Advanced Cluster Management for Kubernetes. Implement network policies to limit incoming connections to only trusted sources that require access to the search API. This will reduce the attack surface for unauthenticated denial-of-service attempts. After applying network policies, ensure that the `search-v2-api` pod is restarted to apply the new network rules effectively. Workaround: To mitigate this issue, restrict permissions for creating and modifying Search Custom Resources (CRs) to only trusted and authorized users. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit who can perform `create`, `update`, and `patch` operations on `search.search.open-cluster-management.io` resources. This reduces the attack surface by preventing unauthorized users from exploiting the unsanitized input flow. Workaround: To mitigate this issue, restrict patch access to the Search Custom Resource (CR) to only trusted and authorized hub administrators. This limits the ability of unauthorized principals to modify the `Collector.ImageOverride` field and deploy arbitrary container images across the managed fleet. Workaround: Ensure glog verbosity on the insights-client Deployment is set below level 2 (-v=0 or -v=1). If CCX_TOKEN must be configured for disconnected environments, restrict access to pod logs in the open-cluster-management namespace and to centralized logging backends. Workaround: Restrict the insights-client ClusterRole to the minimum required permissions. Replace the cluster-wide secrets get/list/watch with a namespaced Role granting get access only to the specific Secret openshift-config/pull-secret in the openshift-config namespace. Workaround: To mitigate this issue, Red Hat Advanced Cluster Management for Kubernetes administrators should configure the application-manager addon to use the least-privilege RBAC variant. This involves applying the addon/manifests/permission/role.yaml configuration, which restricts the permissions granted to the application-manager ServiceAccount. Consult Red Hat documentation for specific instructions on how to apply custom RBAC configurations for RHACM addons. Applying this…

🔗 References (45)