CVE-2026-89060
A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-551
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Weakness type
Related vulnerabilities
- CVE-2023-23924 — URI validation failure on SVG parsing in Dompdf
- CVE-2021-34429 — For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
- CVE-2021-28164 — In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
- CVE-2021-28165 — In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re
- CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction
- CVE-2023-6394 — Quarkus: graphql operations over websockets bypass
- CVE-2021-31384 — Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
- CVE-2021-32779 — Incorrectly handling of URI '#fragment' element as part of the path element