CVE-2026-71846
CVE-2026-71846 is a medium-severity vulnerability in Redhat Advanced Cluster Management For Kubernetes with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-250.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (5th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-250
- Affected product: Redhat Advanced Cluster Management For Kubernetes
- Published:
- Last modified:
Description
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount token would grant an attacker read access to all Secrets across the hub cluster, including managed-cluster kubeconfigs and other sensitive credentials.
Frequently asked questions
- What is CVE-2026-71846?
- A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount token would grant an attacker read access to all Secrets across the hub cluster, including managed-cluster kubeconfigs and other sensitive credentials.
- How severe is CVE-2026-71846?
- CVE-2026-71846 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-71846 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (5th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-71846?
- CVE-2026-71846 primarily affects Redhat Advanced Cluster Management For Kubernetes. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-71846?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-71846 published?
- CVE-2026-71846 was published on 2026-08-12 and last updated on 2026-09-05.
References
- https://access.redhat.com/errata/RHSA-2026:60386
- https://access.redhat.com/errata/RHSA-2026:60387
- https://access.redhat.com/errata/RHSA-2026:60388
- https://access.redhat.com/errata/RHSA-2026:60389
- https://access.redhat.com/errata/RHSA-2026:60390
- https://access.redhat.com/errata/RHSA-2026:60391
- https://access.redhat.com/security/cve/CVE-2026-71846
- https://bugzilla.redhat.com/show_bug.cgi?id=2512569
Affected products (2)
- cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:insights-client:-:*:*:*:*:*:*:*
More vulnerabilities in Redhat Advanced Cluster Management For Kubernetes
- CVE-2026-4740 — High (CVSS 8.2): A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM).…
- CVE-2023-3027 — High (CVSS 7.8): The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain…
- CVE-2022-3841 — High (CVSS 7.8): RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in…
- CVE-2025-14874 — High (CVSS 7.5): A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header…
- CVE-2023-44487 — High (CVSS 7.5): The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset…
- CVE-2022-27191 — High (CVSS 7.5): The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a…
All CVEs affecting Redhat Advanced Cluster Management For Kubernetes →
Other CWE-250 vulnerabilities
- CVE-2026-4606 — Critical (CVSS 10.0): GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing…
- CVE-2022-2634 — Critical (CVSS 10.0): An attacker may be able to execute malicious actions due to the lack of device access protections and device…
- CVE-2026-70496 — Critical (CVSS 9.9): A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster…
- CVE-2026-72508 — Critical (CVSS 9.9): A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM).…
- CVE-2026-48584 — Critical (CVSS 9.9): Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a…
- CVE-2026-50566 — Critical (CVSS 9.9): Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and…