{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-17107", "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "state": "PUBLISHED", "assignerShortName": "redhat", "dateReserved": "2026-07-24T15:28:38.469Z", "datePublished": "2026-07-24T18:56:05.194Z", "dateUpdated": "2026-07-29T16:41:24.469Z" }, "containers": { "cna": { "title": "Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster", "metrics": [ { "other": { "content": { "value": "Important", "namespace": "https://access.redhat.com/security/updates/classification/" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS" } ], "descriptions": [ { "lang": "en", "value": "A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster." } ], "affected": [ { "vendor": "Red Hat", "product": "multicluster engine for Kubernetes 2.10", "collectionURL": "https://catalog.redhat.com/software/containers/", "packageName": "multicluster-engine/cluster-proxy-rhel9", "defaultStatus": "affected", "versions": [ { "version": "1784342329", "lessThan": "*", "versionType": "rpm", "status": "unaffected" } ], "cpes": [ "cpe:/a:redhat:multicluster_engine:2.10::el9" ] }, { "vendor": "Red Hat", "product": "multicluster engine for Kubernetes 2.10", "collectionURL": "https://catalog.redhat.com/software/containers/", "packageName": "multicluster-engine/cluster-proxy-rhel9", "defaultStatus": "affected", "versions": [ { "version": "1784342329", "lessThan": "*", "versionType": "rpm", "status": "unaffected" } ], "cpes": [ "cpe:/a:redhat:multicluster_engine:2.10::el9" ] }, { "vendor": "Red Hat", "product": "multicluster engine for Kubernetes 2.11", "collectionURL": "https://catalog.redhat.com/software/containers/", "packageName": "multicluster-engine/cluster-proxy-rhel9", "defaultStatus": "affected", "versions": [ { "version": "1784925025", "lessThan": "*", "versionType": "rpm", "status": "unaffected" } ], "cpes": [ "cpe:/a:redhat:multicluster_engine:2.11::el9" ] }, { "vendor": "Red Hat", "product": "multicluster engine for Kubernetes 2.6", "collectionURL": "https://catalog.redhat.com/software/containers/", "packageName": "multicluster-engine/cluster-proxy-rhel9", "defaultStatus": "affected", "versions": [ { "version": "1783985960", "lessThan": "*", "versionType": "rpm", "status": "unaffected" } ], "cpes": [ "cpe:/a:redhat:multicluster_engine:2.6::el9" ] }, { "vendor": "Red Hat", "product": "multicluster engine for Kubernetes 2.8", "collectionURL": "https://catalog.redhat.com/software/containers/", "packageName": "multicluster-engine/cluster-proxy-rhel9", "defaultStatus": "affected", "versions": [ { "version": "1784342329", "lessThan": "*", "versionType": "rpm", "status": "unaffected" } ], "cpes": [ "cpe:/a:redhat:multicluster_engine:2.8::el9" ] }, { "vendor": "Red Hat", "product": "multicluster engine for Kubernetes 2.9", "collectionURL": "https://catalog.redhat.com/software/containers/", "packageName": "multicluster-engine/cluster-proxy-rhel9", "defaultStatus": "affected", "versions": [ { "version": "1783278220", "lessThan": "*", "versionType": "rpm", "status": "unaffected" } ], "cpes": [ "cpe:/a:redhat:multicluster_engine:2.9::el9" ] } ], "references": [ { "url": "https://access.redhat.com/errata/RHSA-2026:46885", "name": "RHSA-2026:46885", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ] }, { "url": "https://access.redhat.com/errata/RHSA-2026:47388", "name": "RHSA-2026:47388", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ] }, { "url": "https://access.redhat.com/errata/RHSA-2026:47735", "name": "RHSA-2026:47735", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ] }, { "url": "https://access.redhat.com/errata/RHSA-2026:47949", "name": "RHSA-2026:47949", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ] }, { "url": "https://access.redhat.com/errata/RHSA-2026:47953", "name": "RHSA-2026:47953", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ] }, { "url": "https://access.redhat.com/errata/RHSA-2026:47974", "name": "RHSA-2026:47974", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ] }, { "url": "https://access.redhat.com/security/cve/CVE-2026-17107", "tags": [ "vdb-entry", "x_refsource_REDHAT" ] }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2506771", "name": "RHBZ#2506771", "tags": [ "issue-tracking", "x_refsource_REDHAT" ] } ], "datePublic": "2026-07-24T18:49:48.386Z", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-441", "description": "Unintended Proxy or Intermediary ('Confused Deputy')", "lang": "en", "type": "CWE" } ] } ], "x_redhatCweChain": "CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')", "workarounds": [ { "lang": "en", "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability." } ], "timeline": [ { "lang": "en", "time": "2026-05-22T00:00:00.000Z", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2026-07-24T18:49:48.386Z", "value": "Made public." } ], "credits": [ { "lang": "en", "value": "Red Hat would like to thank Arpit Jain (GitHub: arpitjain099) and Kahiro Okina (Craftsman Software, Inc.) for reporting this issue." } ], "providerMetadata": { "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat", "dateUpdated": "2026-07-29T16:41:24.469Z" }, "x_generator": { "engine": "cvelib 1.8.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-07-27T17:20:52.949389Z", "id": "CVE-2026-17107", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-27T17:21:07.015Z" } } ] } }