CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-17107

highCVSS 8.5covered by 1 sourcefirst seen 2026-07-24
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.

⚡ Watch CVE-2026-17107

Get an email if CVE-2026-17107 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-17107

CVE.org record

Embed the live status

CVE-2026-17107 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-17107 status](https://www.csirts.com/badge/CVE-2026-17107)](https://www.csirts.com/cve/CVE-2026-17107)