Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update
Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.
AI Analysis
Technical Summary
The vulnerability in Grafana Pyroscope allows an attacker with direct access to the Pyroscope API to extract the secret_key configuration value if Tencent COS is used as the storage backend. This exposure of sensitive credentials can lead to unauthorized access to storage resources. The issue affects versions prior to 1.15.2 for the 1.15.x series, prior to 1.16.1 for the 1.16.x series, and all versions before 1.17.0 in the 1.17.x series. The vulnerability is rated critical with a CVSS 3.1 score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating network exploitable with no privileges or user interaction required, causing high confidentiality and integrity impact but no availability impact. The vendor has released fixed versions to address this issue.
Potential Impact
An attacker who can directly access the Pyroscope API and if the system is configured to use Tencent COS as the storage backend can extract the secret_key configuration value. This compromises the confidentiality and integrity of the secret_key, potentially allowing unauthorized access or manipulation of storage resources. The vulnerability does not impact availability. The CVSS score of 9.1 reflects critical severity due to the ease of exploitation and high impact on confidentiality and integrity.
Mitigation Recommendations
A fix is available in Pyroscope versions 1.15.2 and above for the 1.15.x series, 1.16.1 and above for the 1.16.x series, and all 1.17.x versions starting from 1.17.0. Users should upgrade to these fixed versions to remediate the vulnerability. Additionally, it is highly recommended to limit public internet exposure of the Pyroscope API to trusted users or internal systems only, reducing the attack surface. Patch status is confirmed by the vendor advisory.
Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update
Description
Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.
CVSS v3.1
Score 9.1critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Grafana Pyroscope allows an attacker with direct access to the Pyroscope API to extract the secret_key configuration value if Tencent COS is used as the storage backend. This exposure of sensitive credentials can lead to unauthorized access to storage resources. The issue affects versions prior to 1.15.2 for the 1.15.x series, prior to 1.16.1 for the 1.16.x series, and all versions before 1.17.0 in the 1.17.x series. The vulnerability is rated critical with a CVSS 3.1 score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating network exploitable with no privileges or user interaction required, causing high confidentiality and integrity impact but no availability impact. The vendor has released fixed versions to address this issue.
Potential Impact
An attacker who can directly access the Pyroscope API and if the system is configured to use Tencent COS as the storage backend can extract the secret_key configuration value. This compromises the confidentiality and integrity of the secret_key, potentially allowing unauthorized access or manipulation of storage resources. The vulnerability does not impact availability. The CVSS score of 9.1 reflects critical severity due to the ease of exploitation and high impact on confidentiality and integrity.
Mitigation Recommendations
A fix is available in Pyroscope versions 1.15.2 and above for the 1.15.x series, 1.16.1 and above for the 1.16.x series, and all 1.17.x versions starting from 1.17.0. Users should upgrade to these fixed versions to remediate the vulnerability. Additionally, it is highly recommended to limit public internet exposure of the Pyroscope API to trusted users or internal systems only, reducing the attack surface. Patch status is confirmed by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:24503
- Cve Count
- 12
- Additional Cves
- ["CVE-2026-21728","CVE-2026-32281","CVE-2026-32282","CVE-2026-33813","CVE-2026-33815","CVE-2026-33816","CVE-2026-34040","CVE-2026-40293","CVE-2026-40890","CVE-2026-41602","CVE-2026-43869"]
- Cvss Version
- 3.1
Threat ID: 6a27320be29bf47b509be643
Added to database: 06/08/2026, 21:20:11 UTC
Last enriched: 07/30/2026, 15:31:01 UTC
Last updated: 07/31/2026, 19:22:55 UTC
Views: 185
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.