Remote Code Execution Flaw in Multicluster Global Hub by Red Hat
CVE-2026-71576

8.5HIGH

What is CVE-2026-71576?

A vulnerability in Red Hat's Multicluster Global Hub allows a remote attacker with access to a managed hub's Kafka client certificate to manipulate the source identity of incoming CloudEvents. This oversight permits the attacker to falsify or even erase vital data, including compliance, inventory, and cluster health information relevant to other hubs, jeopardizing the integrity of the database.

Affected Version(s)

Multicluster Global Hub 1.4.9 1788355599

Multicluster Global Hub 1.7.3 1788377424

Multicluster Global Hub 1.8.2 1788359454

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.