VYPR

multicloud-operators-subscription

by Red Hat

CVEs (5)

  • CVE-2026-67567CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates…

  • CVE-2026-66792CriAug 17, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to…

  • CVE-2026-72508CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly…

  • CVE-2026-73137HigAug 20, 2026
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function…

  • CVE-2026-66878HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause…