What is CVE-2026-71846?
CVE-2026-71846 is an excessive privilege vulnerability in insights-client where the ServiceAccount is bound to a ClusterRole that grants cluster-wide secret get, list, and watch permissions. This flaw allows an attacker who compromises the insights-client pod to access all secrets in the cluster, requiring organizations to apply patches or restrict the RBAC permissions to only the necessary specific Secret.
Azərbaycanca: CVE-2026-71846, insights-client komponentində həddindən artıq imtiyaz zəifliyidir. Bu zəiflik, ServiceAccount-un klaster üzrə bütün secret resurslarına oxuma icazəsi verən ClusterRole ilə bağlanması səbəbindən, insights-client pod-unun kompromatə olunması halında təcavüzkarın klasterdəki bütün həssas məlumatlara çıxış əldə etməsinə imkan yaradır. Bu riski aradan qaldırmaq üçün təşkilatlar dərhal patchi tətbiq etməli və ya Role-Based Access Control (RBAC) qaydalarını yalnız tələb olunan spesifik Secret ilə məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What access does the CVE-2026-71846 vulnerability provide an attacker through a compromised insights-client pod?
This flaw allows an attacker to access all secrets in the cluster.
How should organizations configure RBAC permissions to mitigate the risk of CVE-2026-71846?
The RBAC permissions should be restricted to only the necessary specific Secret.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.