When RKE provisions a cluster, it stores the cluster state in a configmap called full-cluster-state
inside the kube-system
namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.