Flaw in Red Hat Advanced Cluster Management Allows Token Manipulation
CVE-2026-70398
9.6CRITICAL
What is CVE-2026-70398?
A vulnerability exists within the multicloud-integrations component of Red Hat Advanced Cluster Management that permits an authenticated tenant to manipulate the GitOpsCluster controller. This exploitation enables the tenant to redirect sensitive bearer tokens from secure storage areas to virtual namespaces they control, resulting in unauthorized access. Such access can compromise sensitive data and undermine security policies implemented within ArgoCD AppProjects, posing significant risks to the integrity and confidentiality of the managed clusters.