Sensitive Information Exposure in Multicluster Global Hub by Red Hat
CVE-2026-71577

6.3MEDIUM

What is CVE-2026-71577?

A security flaw has been identified in Multicluster Global Hub that compromises the integrity of managed clusters during a ManagedClusterMigration. The vulnerability arises from improper permission settings, allowing all managed hubs to gain read access to a common communication topic. This inappropriate access enables a compromised hub to intercept sensitive bootstrap kubeconfigs, which contain API server tokens. These tokens, characterized by an extraordinarily long validity period of nearly 10 years, pose a significant risk, potentially leading to unauthorized data access and severe information disclosure across managed clusters.

Affected Version(s)

Multicluster Global Hub 1.4.9 1788355417

Multicluster Global Hub 1.7.3 1788372439

Multicluster Global Hub 1.8.2 1788359461

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.