CVE-2026-107176

Description

A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grants get, list, and watch permissions on all Secret resources without resourceNames scoping. The operator only requires access to the pull-secret Secret. If the samples-operator pod or its service account token is compromised through a separate vulnerability, an attacker could read all secrets in openshift-config, potentially including OAuth identity provider credentials, cloud provider credentials, and other sensitive cluster configuration.

Statement

A flaw was found in the cluster-samples-operator where the RBAC Role coreos-pull-secret-reader (https://github.com/openshift/cluster-samples-operator/blob/release-5.1/manifests/05-kube-system-rbac.yaml#L1-L17) grants overly broad read access to secrets in the openshift-config namespace. The Role allows get, list, and watch on all secrets resources without a resourceNames restriction, although the operator only reads the single secret named pull-secret (https://github.com/openshift/cluster-samples-operator/blob/release-5.1/pkg/metrics/metrics.go#L182). Exploitation requires a prior compromise of the samples-operator pod or its service account token. Red Hat rates this as Moderate impact because the excessive RBAC permissions can only be leveraged after an attacker gains code execution within the operator pod or access to the service account token through a separate vulnerability.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.8N/A6.8
Attack VectorAdjacent NetworkN/AAdjacent Network
Attack ComplexityLowN/ALow
Privileges RequiredLowN/ALow
User InteractionNoneN/ANone
ScopeChangedN/AChanged
ConfidentialityHighN/AHigh
Integrity ImpactNoneN/ANone
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

cve.org: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands; Read Application Data; DoS: Crash, Exit, or Restart

An attacker will be able to gain access to any resources that are allowed by the extra privileges. Common results include executing code, disabling services, and reading restricted data. New weaknesses can be exposed because running with extra privileges, such as root or Administrator, can disable the normal security checks being performed by the operating system or surrounding environment. Other pre-existing weaknesses can turn into security vulnerabilities if they occur while operating at raised privileges.

Frequently Asked Questions

Want to get errata notifications? Sign up here.