CVE-2026-72526
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.42%
- CWE
- CWE-441
- Published
- 2026-08-12
- Last modified
- 2026-09-05
Affected products
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16
Weakness type
Related vulnerabilities
- CVE-2026-87502 — Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87442 — Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-87453 — Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-69531 — Microsoft Windows Speech Tampering Vulnerability
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86115 — Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ Path
- CVE-2026-84329 — Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed...