CVE-2026-10090 – Red Hat Advanced Cluster Management for Kubernetes 2

CVSS 9 CRITICAL Critical - Same Day Deployment

“A namespace-level user can turn a trusted deployment controller into a path to full cluster-admin control.”

CVE-2026-10090 is a Critical privilege escalation vulnerability in the Application Subscription controller. The CVSS score is 9.0, which is Critical severity. A user with namespace-scoped edit privileges can supply a controlled Helm chart containing cluster-scoped resources that the controller applies using its elevated authority.

Successful exploitation can create a ClusterRoleBinding that grants the attacker full cluster-admin privileges, allowing compromise of the Kubernetes cluster.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-267
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.