
Red Hat ACM Flaw Lets Namespace Editors Escalate to Full Kubernetes Cluster Admin
Red Hat has disclosed a critical privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a user with limited namespace-level editing permissions to obtain full cluster-admin access across a Kubernetes environment. Tracked as CVE-2026-10090, the vulnerability affects the Application Subscription controller, also known as multicluster-operators-subscription. Red Hat assigned the issue […]
The post Red Hat ACM Flaw Lets Namespace Editors Escalate to Full Kubernetes Cluster Admin appeared first on Cyber Security News.