PatchDayAlert

CVE

CVE-2026-72508

0field notes · 1digest CVSS 9.9

The verdict

A namespace-scoped admin in RHACM can create Subscription Custom Resources that piggyback on a highly privileged ServiceAccount. This confused-deputy attack lets them deploy arbitrary cluster-scoped resources, effectively escalating from namespace admin to full cluster control. No special tooling required: just the ability to create Subscription CRs in your namespace.

Patch urgency · Patch within 24 hours


Daily digests