CVE-2026-7163
redhat · multicluster engine for kubernetes
What's the vulnerability?
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.
Business impact & how R4IM helps
This advisory is on our active-exploitation watchlist. Attackers are using it for initial access, privilege escalation or lateral movement in real-world intrusions. R4IM's offensive security and SOC teams already have detections, exploit replicas and remediation playbooks for this issue.
Targeted vulnerability assessment to confirm which of your assets are actually exploitable — not just theoretically affected.
Our pentesters chain this CVE into realistic attack paths so you see business impact, not just a scan finding.
If the affected product is internet-facing, our AppSec team will harden it against this and related OWASP-class issues.
Continuous monitoring with custom detections for this CVE deployed across your endpoints, identity and cloud.
Recommended remediation
- Inventory all assets running the affected vendor and product, including shadow IT and third-party hosted instances.
- Apply the vendor patch or mitigation referenced in the advisories below. Where no patch exists, isolate the asset or restrict network exposure.
- Hunt for indicators of prior compromise — exploitation of this class of bug often predates public disclosure.
- Deploy detections for the exploit primitives (network signature, EDR rule, WAF rule) and re-test after remediation.
Need help executing these steps? Our team typically completes validation and remediation within a single patch cycle. Request remediation support →
Vendor & research references
- https://access.redhat.com/errata/RHSA-2026:11511 · secalert@redhat.com
- https://access.redhat.com/errata/RHSA-2026:11512 · secalert@redhat.com
- https://access.redhat.com/errata/RHSA-2026:12116 · secalert@redhat.com
- https://access.redhat.com/errata/RHSA-2026:12337 · secalert@redhat.com
- https://access.redhat.com/errata/RHSA-2026:18584 · secalert@redhat.com
- https://access.redhat.com/errata/RHSA-2026:18585 · secalert@redhat.com
- https://access.redhat.com/security/cve/CVE-2026-7163 · secalert@redhat.com
- https://bugzilla.redhat.com/show_bug.cgi?id=2463152 · secalert@redhat.com
- https://access.redhat.com/errata/RHSA-2026:11511 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:11512 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:12116 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:12337 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:18584 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/errata/RHSA-2026:18585 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://access.redhat.com/security/cve/CVE-2026-7163 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- https://bugzilla.redhat.com/show_bug.cgi?id=2463152 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
