Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.4%top 67%

Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update

0
High
Published: 06/08/2026 (06/08/2026, 14:02:51 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat multicluster global hub is a set of components that enable you to import one or more hub clusters and manage them from a single hub cluster.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

Affected versions
Red HatMulticluster Global HubMulticluster Global Hub 1.7.2amd64registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:90153b5c4c5deeb7abadc7ac8ebb96b9ac72825ef609e8a172cb6866f3db351d_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 15:31:01 UTC

Technical Analysis

The vulnerability in Grafana Pyroscope allows an attacker with direct access to the Pyroscope API to extract the secret_key configuration value if Tencent COS is used as the storage backend. This exposure of sensitive credentials can lead to unauthorized access to storage resources. The issue affects versions prior to 1.15.2 for the 1.15.x series, prior to 1.16.1 for the 1.16.x series, and all versions before 1.17.0 in the 1.17.x series. The vulnerability is rated critical with a CVSS 3.1 score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), indicating network exploitable with no privileges or user interaction required, causing high confidentiality and integrity impact but no availability impact. The vendor has released fixed versions to address this issue.

Potential Impact

An attacker who can directly access the Pyroscope API and if the system is configured to use Tencent COS as the storage backend can extract the secret_key configuration value. This compromises the confidentiality and integrity of the secret_key, potentially allowing unauthorized access or manipulation of storage resources. The vulnerability does not impact availability. The CVSS score of 9.1 reflects critical severity due to the ease of exploitation and high impact on confidentiality and integrity.

Mitigation Recommendations

A fix is available in Pyroscope versions 1.15.2 and above for the 1.15.x series, 1.16.1 and above for the 1.16.x series, and all 1.17.x versions starting from 1.17.0. Users should upgrade to these fixed versions to remediate the vulnerability. Additionally, it is highly recommended to limit public internet exposure of the Pyroscope API to trusted users or internal systems only, reducing the attack surface. Patch status is confirmed by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:24503
Cve Count
12
Additional Cves
["CVE-2026-21728","CVE-2026-32281","CVE-2026-32282","CVE-2026-33813","CVE-2026-33815","CVE-2026-33816","CVE-2026-34040","CVE-2026-40293","CVE-2026-40890","CVE-2026-41602","CVE-2026-43869"]
Cvss Version
3.1

Threat ID: 6a27320be29bf47b509be643

Added to database: 06/08/2026, 21:20:11 UTC

Last enriched: 07/30/2026, 15:31:01 UTC

Last updated: 07/31/2026, 19:22:55 UTC

Views: 185

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses