CVE-2026-67567Disclosure

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-08-20); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-08-20: 3Mentions · 2026-08-21: 1Mentions · 2026-08-24: 1Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-21: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-26: 108-2008-2108-2408-26
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-203
Disclosure3
2026-08-211
Disclosure1
2026-08-241
Disclosure1
2026-08-261
Patch1
Full discourse6 posts
  • Sami Laiho@samilaiho
    Patch

    Red Hat: Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67567 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9

    Post summary

    A critical vulnerability (CVE‑2026‑67567) has been identified with an official fix available; no proof‑of‑concept, exploit code, or active exploitation is reported.

    00010692
    30.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-67567 (CVSS 9.9) leads three Red Hat privilege escalation flaws in ACM and FreeIPA. Two FreeIPA bugs can reach full domain compromise. #RedHat #CVE202667567 #PrivilegeEscalation #FreeIPA #Kubernetes #ACM http://securityonline.info/red-hat-privilege-escalation-cve-2026-67567/

    Post summary

    The text announces CVE-2026-67567, a high‑severity privilege escalation flaw affecting Red Hat ACM and FreeIPA, with two bugs capable of full domain compromise, and provides a link that likely contains further details.

    00010436
    12.9K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-67567 (CVSS 9.9): Red Hatの脆弱性により、ACMおよびFreeIPAで権限昇格が可能になる CVE-2026-67567 (CVSS 9.9): Red Hat Flaws Enable Privilege Escalation in ACM and FreeIPA #DailyCyberSecurity (Aug 21) https://securityonline.info/red-hat-privilege-escalation-cve-2026-67567/

    Post summary

    The post announces CVE‑2026‑67567, a high‑severity privilege escalation flaw affecting Red Hat ACM and FreeIPA, without detailing any PoC, exploit code, or mitigation.

    00000321
    4.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-67567 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (C… https://www.cve.org/CVERecord?id=CVE-2026-67567 ----- Traducción: Se encontró una fa… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑67567, describing a flaw in the multicloud‑operators‑subscription component that grants tenants the ability to create HelmRelease custom resources, but it offers no PoC, exploit code, or patch information.

    0000025
    102 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Red Hat Advanced Cluster Management for Kubernetes (CVE-2026-67567) https://vuldb.com/vuln/393860

    Post summary

    The short message announces that a new CVE (CVE-2026-67567) affecting Red Hat Advanced Cluster Management for Kubernetes has been added to a vulnerability database.

    0000096
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-67567 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (C… https://www.cve.org/CVERecord?id=CVE-2026-67567

    Post summary

    The text announces the discovery of a flaw in the multicloud-operators-subscription component, detailing the potential impact on tenants with HelmRelease custom resource creation privileges.

    000001.1K
    58.0K followersView on X

Explore more