← Terug naar overzicht

A critical vulnerability was identified in the multicloud-operators-subscription component affecting Kubernetes/OpenShift environments. Tenants with the ability to create HelmRelease custom resources can bypass existing security controls. The HelmRelease controller processes Helm chart templates using elevated ServiceAccount privileges without proper validation. This allows malicious tenants to deploy arbitrary resources across the entire cluster. The flaw represents a significant privilege escalation and tenant isolation bypass. It can lead to full cluster compromise by an otherwise limited tenant. The vulnerability is tracked as CVE-2026-67567 and has been reported by Red Hat. A corresponding Bugzilla report (2514224) has been filed for remediation tracking.

Affected products

  • HelmRelease controller
  • Red Hat Advanced Cluster Management
  • multicloud-operators-subscription

Related CVE's

  • CVE-2026-67567

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Zero-Day Vulnerabilities