Back to overview

CVE-2026-17107

HIGH
8.5
CVSS 3.1
Description
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.

Metadata

CVE ID
CVE-2026-17107
State
PUBLISHED
Assigner
redhat
Reserved
2026-07-24 15:28 UTC
Published
2026-07-24 18:56 UTC
Last updated
2026-07-24 18:56 UTC
Primary CWE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
Vendor / Product
Red Hat / Multicluster Engine for Kubernetes
Sources
cve.org  ·  NVD

Severity & Metrics

8.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Red Hat Multicluster Engine for Kubernetes
Weakness (CWE)
CWESourceDescription
CWE-441 cna Unintended Proxy or Intermediary ('Confused Deputy')
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview