What is CVE-2026-17107?
CVE-2026-17107 is a security flaw in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The vulnerability allows callers to inject impersonation group headers into proxied requests, potentially leading to privilege escalation. Mitigation requires applying the relevant security patches.
Azərbaycanca: CVE-2026-17107: Red Hat Advanced Cluster Management for Kubernetes (RHACM) və multicluster-engine (MCE) həllərində istifadə edilən cluster-proxy service-proxy komponentində aşkar edilmiş boşluqdur. Service-proxy, çağırış edənin təqdim etdiyi impersonation group başlıqlarını təmizləmədən proxied sorğulara əlavə etdiyi üçün, zərərli aktorlar öz icazələrini yüksəldə bilər. Bu boşluğu aradan qaldırmaq üçün müvafiq təhlükəsizlik yamaları tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Red Hat
FAQ2
What is the root cause of CVE-2026-17107?
This vulnerability arises because the cluster-proxy service-proxy component appends caller-supplied impersonation group headers to proxied requests without sanitization.
How can CVE-2026-17107 be mitigated?
Mitigation requires applying the relevant security patches.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.