Vulnerability Description
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-67567
- https://bugzilla.redhat.com/show_bug.cgi?id=2514224
FAQ
What is CVE-2026-67567?
CVE-2026-67567 is a vulnerability with a CVSS score of 9.9 (CRITICAL). A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security c...
How severe is CVE-2026-67567?
CVE-2026-67567 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-67567?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.