{"api_version":"1","generated_at":"2026-09-02T05:11:25+00:00","cve":"CVE-2026-67567","urls":{"html":"https://cve.report/CVE-2026-67567","api":"https://cve.report/api/cve/CVE-2026-67567.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-67567","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-67567"},"summary":{"title":"Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction","description":"A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-08-20 21:17:07","updated_at":"2026-08-28 21:17:10"},"problem_types":["CWE-441","CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514224","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2514224","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60389","name":"https://access.redhat.com/errata/RHSA-2026:60389","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60388","name":"https://access.redhat.com/errata/RHSA-2026:60388","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60387","name":"https://access.redhat.com/errata/RHSA-2026:60387","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60390","name":"https://access.redhat.com/errata/RHSA-2026:60390","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-67567","name":"https://access.redhat.com/security/cve/CVE-2026-67567","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60391","name":"https://access.redhat.com/errata/RHSA-2026:60391","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60386","name":"https://access.redhat.com/errata/RHSA-2026:60386","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-67567","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67567","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.11","version":"unaffected 1787263584 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.13","version":"unaffected 1787263693 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.14","version":"unaffected 1787170830 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.15","version":"unaffected 1787240030 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.16","version":"unaffected 1787242321 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1787242108 * rpm","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-11T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-08-11T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"To mitigate this issue, restrict the ability of untrusted tenants to create `HelmRelease` custom resources within the cluster. Implement strict Role-Based Access Control (RBAC) policies to limit which users or service accounts can create or modify `HelmRelease` objects. This will prevent unauthorized users from leveraging the controller's elevated privileges for cluster-wide resource deployment.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"67567","cve":"CVE-2026-67567","epss":"0.004280000","percentile":"0.356810000","score_date":"2026-08-31","updated_at":"2026-09-01 00:06:29"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-67567","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-21T16:20:26.843480Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-21T16:20:37.245Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.11::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-subscription-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.11","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787263584","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.13::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-subscription-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.13","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787263693","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.14::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-subscription-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.14","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787170830","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.15::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-subscription-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.15","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787240030","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.16::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-subscription-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.16","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787242321","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/multicluster-operators-subscription-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787242108","versionType":"rpm"}]}],"datePublic":"2026-08-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-441","description":"Unintended Proxy or Intermediary ('Confused Deputy')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-27T02:16:16.112Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2026:60386","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60386"},{"name":"RHSA-2026:60387","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60387"},{"name":"RHSA-2026:60388","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60388"},{"name":"RHSA-2026:60389","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60389"},{"name":"RHSA-2026:60390","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60390"},{"name":"RHSA-2026:60391","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60391"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-67567"},{"name":"RHBZ#2514224","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514224"}],"timeline":[{"lang":"en","time":"2026-08-11T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-08-11T00:00:00.000Z","value":"Made public."}],"title":"Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction","workarounds":[{"lang":"en","value":"To mitigate this issue, restrict the ability of untrusted tenants to create `HelmRelease` custom resources within the cluster. Implement strict Role-Based Access Control (RBAC) policies to limit which users or service accounts can create or modify `HelmRelease` objects. This will prevent unauthorized users from leveraging the controller's elevated privileges for cluster-wide resource deployment."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-67567","datePublished":"2026-08-20T20:34:10.321Z","dateReserved":"2026-08-11T17:40:07.959Z","dateUpdated":"2026-08-27T02:16:16.112Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-20 21:17:07","lastModifiedDate":"2026-08-28 21:17:10","problem_types":["CWE-441","CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-21T16:20:26.843480Z","id":"CVE-2026-67567","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"67567","Ordinal":"1","Title":"Multicloud-operators-subscription: multicloud-operators-subscrip","CVE":"CVE-2026-67567","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"67567","Ordinal":"1","NoteData":"A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.","Type":"Description","Title":"Multicloud-operators-subscription: multicloud-operators-subscrip"}]}}}