Bug 2515720 (CVE-2026-75924)

Summary: CVE-2026-75924 managed-serviceaccount: managed-serviceaccount: Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gparvin, rhaigner, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-13 21:15:04 UTC
FIND-002 from Project Glasswing AI-SAST audit of open-cluster-management-io/managed-serviceaccount (audit date 2026-06-10, commit unknown). The open-cluster-management:managed-serviceaccount:addon-manager ClusterRole grants get/list/watch/create/update/patch/delete on secrets cluster-wide plus approve on certificatesigningrequests. A compromised addon-manager pod can read any secret in any namespace and approve arbitrary CSRs.