A flaw was found in the multicloud-integrations component. (CVE-2026-72526)
A critical vulnerability exists in the multicloud-integrations component of Red Hat Advanced Cluster Management. The Application propagation controller improperly validates the ocm-managed-cluster annotation from Application Custom Resources, allowing a tenant with Application creation permissions on the hub cluster to target arbitrary managed clusters. This can force ArgoCD on spoke clusters to synchronize attacker-controlled manifests, resulting in arbitrary code execution or privilege escalation on those clusters.
AI Analysis
Technical Summary
CVE-2026-72526 is a critical security flaw in the multicloud-integrations component of Red Hat Advanced Cluster Management. The vulnerability arises because the Application propagation controller does not properly validate the ocm-managed-cluster annotation in Application Custom Resources. This lack of validation allows a tenant with permissions to create Applications on the hub cluster to redirect ManifestWorks to arbitrary managed spoke clusters. Consequently, this bypasses authorization controls and enables an attacker to cause ArgoCD on those clusters to synchronize malicious manifests, leading to arbitrary code execution or privilege escalation with cluster-admin privileges on the targeted spoke clusters. The flaw is categorized under CWE-441 (Unintended Proxy or Intermediary, 'Confused Deputy').
Potential Impact
An attacker with low privileges (Application creation permissions) on the hub cluster can escalate privileges to cluster-admin on any connected spoke cluster. This enables arbitrary code execution and full control over the targeted managed clusters, severely compromising the managed environment's security and integrity.
Mitigation Recommendations
According to the Red Hat advisory, no official fix or patch is currently available that meets their criteria for ease of use, applicability, and stability. Therefore, no direct remediation is presently provided. Users should monitor Red Hat advisories for updates. Until a fix is released, consider restricting tenant permissions to create Applications on the hub cluster to trusted users only and apply any available compensating controls to limit the impact.
A flaw was found in the multicloud-integrations component. (CVE-2026-72526)
Description
A critical vulnerability exists in the multicloud-integrations component of Red Hat Advanced Cluster Management. The Application propagation controller improperly validates the ocm-managed-cluster annotation from Application Custom Resources, allowing a tenant with Application creation permissions on the hub cluster to target arbitrary managed clusters. This can force ArgoCD on spoke clusters to synchronize attacker-controlled manifests, resulting in arbitrary code execution or privilege escalation on those clusters.
CVSS v3.1
Score 9.9critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-72526 is a critical security flaw in the multicloud-integrations component of Red Hat Advanced Cluster Management. The vulnerability arises because the Application propagation controller does not properly validate the ocm-managed-cluster annotation in Application Custom Resources. This lack of validation allows a tenant with permissions to create Applications on the hub cluster to redirect ManifestWorks to arbitrary managed spoke clusters. Consequently, this bypasses authorization controls and enables an attacker to cause ArgoCD on those clusters to synchronize malicious manifests, leading to arbitrary code execution or privilege escalation with cluster-admin privileges on the targeted spoke clusters. The flaw is categorized under CWE-441 (Unintended Proxy or Intermediary, 'Confused Deputy').
Potential Impact
An attacker with low privileges (Application creation permissions) on the hub cluster can escalate privileges to cluster-admin on any connected spoke cluster. This enables arbitrary code execution and full control over the targeted managed clusters, severely compromising the managed environment's security and integrity.
Mitigation Recommendations
According to the Red Hat advisory, no official fix or patch is currently available that meets their criteria for ease of use, applicability, and stability. Therefore, no direct remediation is presently provided. Users should monitor Red Hat advisories for updates. Until a fix is released, consider restricting tenant permissions to create Applications on the hub cluster to trusted users only and apply any available compensating controls to limit the impact.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-hp26-rmxw-4cpv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72526"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a7c9b67bf8831d539cdf2b2
Added to database: 08/12/2026, 16:12:23 UTC
Last enriched: 08/12/2026, 17:13:16 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.