The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373
```
- apiGroups:
- ""
resources:
- secrets
verbs:
- get
- list
```

By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.

```
spec:
serviceAccountName:"gather"
```
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups: - "" resources: - secrets verbs: - get - list ``` By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace. ``` spec: serviceAccountName:"gather" ```
Title Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and cluster-reader
First Time appeared Redhat
Redhat openshift
Weaknesses CWE-269
CPEs cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat openshift
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T14:31:58.671Z

Reserved: 2026-09-17T14:51:36.301Z

Link: CVE-2026-93017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:56.950

Modified: 2026-10-08T15:17:56.950

Link: CVE-2026-93017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:17Z

Weaknesses