HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-17107 — A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad...

·Source: NIST NVD

Updated:

Executive Summary

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an

Analysis

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster. CVSS Score: 8.5. Published: 2026-07-24T19:16:55.907.

Indicators of Compromise (1)

CVE (1)
CVE-2026-17107
Source Attribution

Originally published by NIST NVD on Jul 24, 2026. Verified by: NIST.

Related Threats