REDHAT-BUG-2515720: High severity open-cluster-management-io/managed-serviceaccount vulnerability

Published Aug 13, 2026
·
Updated

FIND-002 from Project Glasswing AI-SAST audit of open-cluster-management-io/managed-serviceaccount (audit date 2026-06-10, commit unknown). The open-cluster-management:managed-serviceaccount:addon-manager ClusterRole grants get/list/watch/create/update/patch/delete on secrets cluster-wide plus approve on certificatesigningrequests. A compromised addon-manager pod can read any secret in any namespace and approve arbitrary CSRs.

Affected Software

1 affected component
open-cluster-management-io/managed-serviceaccount

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Limit the addon-manager pod’s permissions by removing/avoiding the ClusterRole rules that grant cluster-wide access to Kubernetes Secrets (get/list/watch/create/update/patch/delete) and the ability to approve arbitrary CertificateSigningRequests. Use a tightly scoped Role/RoleBinding limited to the namespaces and specific Secrets/CSRs required for operation, rather than cluster-scoped permissions.

Event History

Aug 13, 2026
Data Sourced
via Red Hat·09:15 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who is exposed to this risk?

Clusters running the managed-serviceaccount addon-manager are exposed if its ClusterRole binding remains in place. A compromise of that pod or its service account would provide cluster-wide access to Secrets and the ability to approve certificate signing requests.

2

What level of access does an attacker need to exploit these permissions?

An attacker needs to compromise the addon-manager pod or obtain credentials for its service account. The granted permissions then allow reading, creating, modifying, and deleting Secrets in any namespace, as well as approving arbitrary CSRs.

3

Is a default installation affected?

The audit data does not state whether this ClusterRole and binding are enabled in a default deployment. Verify whether the open-cluster-management:managed-serviceaccount:addon-manager ClusterRole is bound to the addon-manager service account in your cluster.

4

What can be done while waiting for a fix?

If patching or redesign is not immediately possible, restrict or remove the addon-manager binding's cluster-wide Secret permissions and CSR approval permission where operationally feasible. Review the addon-manager workload and service-account credentials for compromise because those credentials carry the affected privileges.

5

How can I determine whether my cluster is affected?

Inspect the open-cluster-management:managed-serviceaccount:addon-manager ClusterRole for get, list, watch, create, update, patch, and delete permissions on Secrets, and approve permission on certificatesigningrequests. Also review ClusterRoleBindings to determine whether those permissions are assigned to the addon-manager service account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203