Remote Code Execution Flaw in Multicluster Global Hub by Red Hat
CVE-2026-71576

8.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-71576?

A vulnerability in Red Hat's Multicluster Global Hub allows a remote attacker with access to a managed hub's Kafka client certificate to manipulate the source identity of incoming CloudEvents. This oversight permits the attacker to falsify or even erase vital data, including compliance, inventory, and cluster health information relevant to other hubs, jeopardizing the integrity of the database.

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.