Configuration Resource Exposure in Multicluster Observability Addon by Red Hat
CVE-2026-89060
7.7HIGH
What is CVE-2026-89060?
A flaw exists in the multicluster-observability-addon that allows a managed-cluster identity to access configuration resources located outside its designated namespace. This misconfiguration can lead to the unauthorized disclosure of sensitive hub secrets, which potentially enables attackers to gain confidential information from the system. The implications of this vulnerability highlight the importance of secure namespace isolation and proper identity management in multi-cluster environments.