VYPR
High severity7.7NVD Advisory· Published Oct 8, 2026

CVE-2026-93017

CVE-2026-93017

Description

The insights-operator-gather ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 `` - apiGroups: - "" resources: - secrets verbs: - get - list ``

By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.

spec:
 serviceAccountName:"gather"

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.