PT-2026-108025 · Red Hat · Red Hat Openshift Container Platform 4

CVE-2026-93017

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The insights-operator-gather ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.
- apiGroups:
 - ""
 resources:
 - secrets
 verbs:
 - get
 - list
By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.
spec:
 serviceAccountName:"gather"

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-93017

Produtos afetados

Red Hat Openshift Container Platform 4