CVE-2026-10090Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-08-05); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-08-05: 3Mentions · 2026-08-06: 1Mentions · 2026-08-10: 3Mentions · 2026-08-11: 1Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-05: 3Technical Details · 2026-08-06: 1Technical Details · 2026-08-10: 3Technical Details · 2026-08-11: 1Technical Details · 2026-08-18: 108-0508-0608-1008-1108-18
Signal classification3 categories
Disclosure
666.7%
General
222.2%
Patch
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-08-053
Disclosure1General1Patch1
2026-08-061
General1
2026-08-103
Disclosure3
2026-08-111
Disclosure1
2026-08-181
Disclosure1
Full discourse9 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    🚨 A single "edit" permission is all it takes to become a Kubernetes god-mode admin. Here's how CVE-2026-10090 breaks Red Hat ACM wide open. Full story: https://cybersecuritynews.com/red-hat-acm-privilege-escalation-vulnerability/ #cybersecuritynews https://t.co/gfr9x4glNs

    Post summary

    The tweet announces a privilege escalation vulnerability (CVE‑2026‑10090) affecting Red Hat ACM, noting that a single edit permission can lead to god‑mode admin access.

    018055125.5K
    73.3K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad de Red Hat ACM permite acceso total de administrador al clúster Fallo crítico de escalada de privilegios (CVE-2026-10090) que afecta al controlador de suscripciones de aplicaciones en Red Hat Advanced Cluster Management for Kubernetes (ACM) https://blog.elhacker.net/2026/08/vulnerabilidad-de-red-hat-acm-permite.html

    Post summary

    A critical privilege‑escalation vulnerability (CVE‑2026‑10090) affects Red Hat Advanced Cluster Management for Kubernetes, enabling full administrative cluster access; the blog post documents the flaw but does not provide PoC, active exploitation, or patch details.

    0603084.7K
    141.8K followersView on X
  • Sami Laiho@samilaiho
    General

    Red Hat - Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10090 Classification: Critical, CVSSv3.1: 9.9

    Post summary

    CVE-2026-10090 allows a namespace‑edit user in Red Hat’s multicluster‑operators‑subscription to deploy a cluster‑scoped clusterrolebinding and obtain cluster‑admin privileges, classified as critical with a CVSS score of 9.9.

    01010693
    30.6K followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    A critical flaw (CVE-2026-10090) in Red Hat's Advanced Cluster Management for Kubernetes allows users with basic edit permissions to escalate to full cluster-admin rights, posing significant security risks. Organizations should audit access controls and monitor resource creation closely. #RedHat #ACM #Kubernetes #Security #CVE202610090 #CyberSecurity https://thedailytechfeed.com/critical-privilege-escalation-vulnerability-in-red-hat-acm/

    Post summary

    The post discloses a critical privilege escalation flaw in Red Hat's Advanced Cluster Management for Kubernetes that permits users with edit rights to assume cluster‑admin permissions, with no PoC, exploit, or patch details provided.

    0001069
    618 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 Red Hat ACM/MCE Privilege Escalation Bundle — CVSS 9.9 + 9.1 CVE-2026-10090 (ACM) + CVE-2026-10059 (MCE): Namespace access → Full cluster-admin. Patch to 2.9.2/2.8.5/2.5.2/2.4.5 NOW. → http://threataft.com/articles/red-hat-acm-mce-cve-2026-10090-cve-2026-10059 #cybersecurity #infosec #RedHat #Kubernetes #ThreatIntel

    Post summary

    The post alerts to high‑severity privilege escalation CVEs in Red Hat ACM/MCE, provides patch versions, and links to further details.

    0000156
    36 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-10090 Privilege Escalation in Red Hat Advanced Cluster Management for Kubernetes Subscription Controller https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-10090

    Post summary

    The note only references CVE-2026-10090 as a privilege‑escalation issue in Red Head Advanced Cluster Management for Kubernetes, linking to a vulnerability details page; it provides no PoC, exploit, patch, or further technical specifics.

    00010117
    4.1K followersView on X
  • VulniPulse@vulnipulse
    Disclosure

    🚨 CRITICAL CVE ALERT CVE-2026-10090 · Linux Red Hat Advanced Cluster Management for · CVSS 9.9 Attackers could elevate privileges. 🔎 Full advisory: https://vulnipulse.com/advisories/linux-cve-2026-10090 #CyberSecurity #CVE #Linux #RedHatAdvancedClusterManagementfor

    Post summary

    A new critical privilege‑elevation vulnerability (CVE‑2026‑10090) affecting Red Hat Advanced Cluster Management has been announced with a CVSS score of 9.9.

    1000065
    7 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Red Hat ACM の権限昇格の脆弱性 CVE-2026-10090:Cluster-Admin 奪取の恐れ https://iototsecnews.jp/2026/08/10/red-hat-acm-privilege-escalation-vulnerability-lets-attackers-gain-full-cluster-admin-access/ Red Hat Advanced Cluster Management for Kubernetes (Red Hat ACM) における認可処理の不足が、この問題の大きな背景となっています。この機能では要求元の権限検証が適切に行われず、自身に割り当てられた強い権限でリソース処理が実行されてしまいます。これにより、限定的な権限しか持たない利用者であっても、悪意のある記述を含む設定を配置することで管理者権限(cluster-admin)を不正に取得できてしまいます。結果として管理下の環境全体が制御される重大な影響が生じます。対応策としては、ハブ名前空間での権限監査/非認可リソースへの参照監視/信頼された運用者への権限制限/入場制御ポリシーによる無効化などの実施が推奨されます。 #AdvancedClusterManagementforKubernetes #CVE202610090 #RedHat #Vulnerability

    Post summary

    The article announces CVE-2026-10090, a privilege‑escalation flaw in Red Hat Advanced Cluster Management for Kubernetes that lets low‑privilege users acquire cluster‑admin rights via malicious configuration, and outlines mitigation steps.

    00000215
    507 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-10090 lets an edit-scoped user gain cluster-admin in Red Hat ACM for Kubernetes. Privilege escalation rated CVSS 9.9. #RedHat #Kubernetes #CVE #PrivilegeEscalation #CyberSecurity http://securityonline.info/red-hat-acm-privilege-escalation/

    Post summary

    The post announces a high-severity privilege escalation vulnerability (CVSS 9.9) in Red Hat ACM for Kubernetes, noting that an edit-scoped user can obtain cluster‑admin rights, but provides no proof of concept, exploit code, or evidence of active exploitation.

    00000451
    12.6K followersView on X

Explore more