CVE
CVE-2026-72508
0field notes · 1digest CVSS 9.9
The verdict
A namespace-scoped admin in RHACM can create Subscription Custom Resources that piggyback on a highly privileged ServiceAccount. This confused-deputy attack lets them deploy arbitrary cluster-scoped resources, effectively escalating from namespace admin to full cluster control. No special tooling required: just the ability to create Subscription CRs in your namespace.
Patch urgency · Patch within 24 hours
Daily digests