CVE-2026-71846

Summary

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount token would grant an attacker read access to all Secrets across the hub cluster, including managed-cluster kubeconfigs and other sensitive credentials.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.111787688993 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.131787259125 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.141786882244 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.151787238585 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.161787184541 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171787227689 < *unaffected

Weaknesses

  • CWE-250: Execution with Unnecessary Privileges

Workarounds

Restrict the insights-client ClusterRole to the minimum required permissions. Replace the cluster-wide secrets get/list/watch with a namespaced Role granting get access only to the specific Secret openshift-config/pull-secret in the openshift-config namespace.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References