What is CVE-2026-10090?
CVE-2026-10090 is a vulnerability in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped 'edit' privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control, posing a potential security risk. ACM users are advised to apply the security update once provided by Red Hat.
Azərbaycanca: CVE-2026-10090 Red Hat Advanced Cluster Management for Kubernetes (ACM) məhsulunda yerləşən 'Application Subscription' kontrollerində (multicluster-operators-subscription) aşkarlanmış boşluqdur. ACM hub namespace-də 'edit' səlahiyyəti olan istifadəçi öz nəzarətindəki Helm repozitoriyasına işarə edən Channel resursu yarada bilər ki, bu da potensial təhlükəsizlik riskinə səbəb olur. ACM istifadəçilərinə Red Hat tərəfindən təqdim ediləcək təhlükəsizlik yeniləməsini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: Red Hat
FAQ2
What product does CVE-2026-10090 affect?
CVE-2026-10090 affects the Application Subscription controller in Red Hat Advanced Cluster Management for Kubernetes (ACM).
What action can a user with 'edit' privileges in an ACM hub namespace perform?
The user can create a Channel resource pointing to a Helm repository they control.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.