Flaw in Red Hat Advanced Cluster Management Allows Token Manipulation
CVE-2026-70398

9.6CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
12 August 2026

What is CVE-2026-70398?

A vulnerability exists within the multicloud-integrations component of Red Hat Advanced Cluster Management that permits an authenticated tenant to manipulate the GitOpsCluster controller. This exploitation enables the tenant to redirect sensitive bearer tokens from secure storage areas to virtual namespaces they control, resulting in unauthorized access. Such access can compromise sensitive data and undermine security policies implemented within ArgoCD AppProjects, posing significant risks to the integrity and confidentiality of the managed clusters.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.