A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 18 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat multicluster Engine
|
|
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat multicluster Engine
|
Tue, 18 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster. | |
| Title | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants cluster-wide secret read/write and csr approval | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-18T17:58:03.483Z
Reserved: 2026-08-18T15:29:26.756Z
Link: CVE-2026-75924
Updated: 2026-08-18T17:36:36.116Z
Status : Received
Published: 2026-08-18T17:17:03.457
Modified: 2026-08-18T18:19:34.770
Link: CVE-2026-75924
OpenCVE Enrichment
Updated: 2026-08-18T18:15:05Z