SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67567

CRITICAL · CVSS 9.9 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the multicloud-operators-subscription component, allowing tenants with the ability to create HelmRelease custom resources to bypass security controls. This flaw enables the HelmRelease controller to process templates with elevated privileges, permitting the deployment of arbitrary resources throughout the cluster. Organizations utilizing this component should prioritize immediate remediation to prevent potential security breaches.

CVE
CVE-2026-67567
Severity
CRITICAL
CVSS
9.9
EPSS
0.43%

Original NVD Description

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.