CVE-2026-17107
⚠️ highSummary
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.
CVSS Score
8.5
High
EPSS Score
0.4
Exploit Probability
Published Date
2026-07-24
First Seen: 2026-07-31
📊 Relative Risk Intelligence
This CVE is High Risk - more severe than 80.4% of all 340,405 vulnerabilities in our database.
#66,742
Top 25% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jul 27, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Red Hat would like to thank Arpit Jain (GitHub: arpitjain099) and Kahiro Okina (Craftsman Software, Inc.) for reporting this issue.
SSVC data provided by
CISA
Last Modified
2026-07-30
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)