boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-7163

Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  N  N    5.5   .0020    9.3     —
AFFECTED
  Product                                  Versions     Fixed
  assisted-service                         2.7.0 –      —
  multicluster engine for Kubernetes 2.1   unspecified  1776983527
  multicluster engine for Kubernetes 2.11  unspecified  1776987609
  multicluster engine for Kubernetes 2.7   unspecified  1777205801
  multicluster engine for Kubernetes 2.7   unspecified  1777205772
  multicluster engine for Kubernetes 2.9   unspecified  1778464111
  multicluster engine for Kubernetes 2.9   unspecified  1778464072
TIMELINE
  Apr 27  Reserved by redhat
  Apr 30  Published (CNA: redhat)
  Aug 24  RESCORED — CVE-2026-7163 (Red Hat multicluster engine for Kubernetes 2.1). CVSS 6.1 → 5.5 (NVD).
CWE-312 · CNA: redhat · CVSS v3.1 · 9 references · NVD status: Modified

Description

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 27, 2026ReservedReserved by redhat
April 30, 2026PublishedPublished (CNA: redhat)
August 24, 2026RESCOREDRESCORED — CVE-2026-7163 (Red Hat multicluster engine for Kubernetes 2.1). CVSS 6.1 → 5.5 (NVD).

Affected

Affected products and packages — 7 rows
VendorProduct / PackageEcosystemVersion introducedFixed
—assisted-service—2.7.0—
Red Hatmulticluster engine for Kubernetes 2.1——1776983527
Red Hatmulticluster engine for Kubernetes 2.11——1776987609
Red Hatmulticluster engine for Kubernetes 2.7——1777205801
Red Hatmulticluster engine for Kubernetes 2.7——1777205772
Red Hatmulticluster engine for Kubernetes 2.9——1778464111
Red Hatmulticluster engine for Kubernetes 2.9——1778464072

Weaknesses

CWE-312

References (9)

Related

Authoritative record: CVE-2026-7163 at cve.org

Vendors: red hat

Weaknesses: CWE-312

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-7163 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.