CVE-2026-17107

Summary

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.

Affected Software

VendorProductVersion RangeStatus
Red Hatmulticluster engine for Kubernetes 2.11784342329 < *unaffected
Red Hatmulticluster engine for Kubernetes 2.11784342329 < *unaffected
Red Hatmulticluster engine for Kubernetes 2.111784925025 < *unaffected
Red Hatmulticluster engine for Kubernetes 2.171784926298 < *unaffected
Red Hatmulticluster engine for Kubernetes 2.61783985960 < *unaffected
Red Hatmulticluster engine for Kubernetes 2.81784342329 < *unaffected
Red Hatmulticluster engine for Kubernetes 2.9.01783278220 < *unaffected

Weaknesses

  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References