CVE Database
/

CVE-2026-7163

Back to search

CVE-2026-7163

Published: Apr 30, 2026

Modified: May 19, 2026

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.

VendorProductVersions

Red Hat

multicluster engine for Kubernetes 2.10

unaffected
1776983527 - < *

Red Hat

multicluster engine for Kubernetes 2.11

unaffected
1776987609 - < *

Red Hat

multicluster engine for Kubernetes 2.7

unaffected
1777205801 - < *

Red Hat

multicluster engine for Kubernetes 2.7

unaffected
1777205772 - < *

Red Hat

multicluster engine for Kubernetes 2.9

unaffected
1778464111 - < *

Red Hat

multicluster engine for Kubernetes 2.9

unaffected
1778464072 - < *

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

None

Availability

None

References

RHSA-2026:11511
vendor-advisory
x_refsource_REDHAT
RHSA-2026:11512
vendor-advisory
x_refsource_REDHAT
RHSA-2026:12116
vendor-advisory
x_refsource_REDHAT
RHSA-2026:12337
vendor-advisory
x_refsource_REDHAT
RHSA-2026:18584
vendor-advisory
x_refsource_REDHAT
RHSA-2026:18585
vendor-advisory
x_refsource_REDHAT
RHBZ#2463152
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now