CVE-2026-10090 – Red Hat Advanced Cluster Management for Kubernetes 2
CVSS 9
CRITICAL
Critical - Same Day Deployment
“A namespace-level user can turn a trusted deployment controller into a path to full cluster-admin control.”
CVE-2026-10090 is a Critical privilege escalation vulnerability in the Application Subscription controller. The CVSS score is 9.0, which is Critical severity. A user with namespace-scoped edit privileges can supply a controlled Helm chart containing cluster-scoped resources that the controller applies using its elevated authority.
Successful exploitation can create a ClusterRoleBinding that grants the attacker full cluster-admin privileges, allowing compromise of the Kubernetes cluster.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-267
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.