Skip to main content
EPSS 0.2%top 95%

CVE-2026-71846: Execution with Unnecessary Privileges in Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11

0
Medium
Published: 08/12/2026 (08/12/2026, 21:46:19 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: Red Hat Advanced Cluster Management for Kubernetes 2.11

Description

CVE-2026-71846 is a moderate severity vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2.11. The insights-client component's ServiceAccount is granted cluster-wide read permissions on all Secrets, although it only requires access to a single specific Secret. This excessive privilege could allow an attacker who compromises the insights-client pod or its ServiceAccount token to read all Secrets across the hub cluster, including sensitive credentials such as managed-cluster kubeconfigs.

CVSS v3.1

Score 6.5medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 13:05:01 UTC

Technical Analysis

The vulnerability arises from the insights-client component in Red Hat Advanced Cluster Management for Kubernetes 2.11 having a ClusterRole that grants cluster-wide get, list, and watch permissions on Secrets. However, the component only needs access to one specific Secret (openshift-config/pull-secret). This over-broad Role-Based Access Control (RBAC) creates a privilege amplification vector, enabling an attacker who compromises the insights-client pod or ServiceAccount token to read all Secrets in the hub cluster, potentially exposing sensitive credentials and kubeconfigs.

Potential Impact

An attacker who gains control over the insights-client pod or its ServiceAccount token can read all Secrets across the Kubernetes hub cluster. This includes sensitive information such as managed-cluster kubeconfigs and other credentials, leading to potential confidentiality breaches. The vulnerability does not impact integrity or availability but poses a high confidentiality risk.

Mitigation Recommendations

Red Hat recommends restricting the insights-client ClusterRole to the minimum required permissions. Specifically, replace the cluster-wide secrets get, list, and watch permissions with a namespaced Role that grants get access only to the specific Secret openshift-config/pull-secret in the openshift-config namespace. This reduces the privilege scope and mitigates the risk of privilege amplification.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-wfwr-qqxc-6cch
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71846"]
Database Specific Severity
MODERATE
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a7d12d0bf8831d5396c1745

Added to database: 08/13/2026, 00:41:52 UTC

Last enriched: 09/13/2026, 13:05:01 UTC

Last updated: 09/27/2026, 13:47:47 UTC

Views: 87

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses