<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T19:13:40.356328+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-17107</id>
    <title>CVE-2026-17107 — Cluster-proxy: impersonation-header injection grants cluster-admin on every managed cluster</title>
    <updated>2026-10-05T19:13:40.371849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Red Hat multicluster engine for Kubernetes 2.10, Red Hat multicluster engine for Kubernetes 2.11, Red Hat multicluster engine for Kubernetes 2.17, Red Hat multicluster engine for Kubernetes 2.6, Red Hat multicluster engine for Kubernetes 2.8, Red Hat multicluster engine for Kubernetes 2.9</p>
<p>A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-17107"/>
  </entry>
</feed>
