High severity7.7NVD Advisory· Published Oct 8, 2026
CVE-2026-93017
CVE-2026-93017
Description
The insights-operator-gather ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.
Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 `` - apiGroups: - "" resources: - secrets verbs: - get - list ``
By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.
spec:
serviceAccountName:"gather"
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.