{"success":true,"data":{"threats":[{"id":"9b6010f3-d801-48a5-8ad3-e4df20a005c1","slug":"cve-2026-93017","externalId":"CVE-2026-93017","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93017 — The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or …","description":"The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.\n\nRef: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373\n```\n- apiGroups:\n  - \"\"\n  resources:\n  - secrets\n  verbs:\n  - get\n  - list\n```\n\nBy spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.\n\n```\nspec:\n serviceAccountName:\"gather\"\n```","cveId":"CVE-2026-93017","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93017","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515741","type":"advisory","title":"secalert@redhat.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:56.950Z","addedAt":"2026-10-08T16:39:35.972Z","updatedAt":"2026-10-08T21:05:50.579Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93017","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93017","note":"authoritative record"}],"raw":{"id":"CVE-2026-93017","cveTags":[],"metrics":{"cvssMetricV31":[{"type":"Primary","source":"secalert@redhat.com","cvssData":{"scope":"CHANGED","version":"3.1","baseScore":7.7,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"HIGH"},"impactScore":4,"exploitabilityScore":3.1}]},"affected":[{"source":"secalert@redhat.com","affectedData":[{"cpes":["cpe:/a:redhat:openshift:4"],"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","packageName":"openshift4/ose-insights-rhel8-operator","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","defaultStatus":"affected"},{"cpes":["cpe:/a:redhat:openshift:4"],"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","packageName":"openshift4/ose-insights-rhel9-operator","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","defaultStatus":"affected"}]}],"published":"2026-10-08T15:17:56.950","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93017","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515741","source":"secalert@redhat.com"}],"vulnStatus":"Awaiting Analysis","weaknesses":[{"type":"Primary","source":"secalert@redhat.com","description":[{"lang":"en","value":"CWE-269"}]}],"descriptions":[{"lang":"en","value":"The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.\n\nRef: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373\n```\n- apiGroups:\n  - \"\"\n  resources:\n  - secrets\n  verbs:\n  - get\n  - list\n```\n\nBy spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.\n\n```\nspec:\n serviceAccountName:\"gather\"\n```"}],"lastModified":"2026-10-08T20:49:23.240","sourceIdentifier":"secalert@redhat.com"}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:12:05.746Z","durationMs":7,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2026-93017","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}