PT-2026-108025 · Red Hat · Red Hat Openshift Container Platform 4

CVE-2026-93017

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The insights-operator-gather ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.
- apiGroups:
 - ""
 resources:
 - secrets
 verbs:
 - get
 - list
By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.
spec:
 serviceAccountName:"gather"

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93017

Affected Products

Red Hat Openshift Container Platform 4