CVE-2026-93017

EUVD-2026-95030
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.

Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373
```
- apiGroups:
  - ""
  resources:
  - secrets
  verbs:
  - get
  - list
```

By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.

```
spec:
 serviceAccountName:"gather"
```
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N