Impact
A flaw in Red Hat Multicluster GlobalHub allows an attacker who compromises a managed hub to publish a CloudEvent message to the shared gh‑spec Kafka topic. The message can spoof its source as "global‑hub" because the Kafka client principal is not bound to the CloudEvent envelope. The receiving hub accepts this spoofed event and applies the included resources, effectively granting the attacker cluster‑administrator privileges across the entire fleet of managed hubs. This is a classic improper authentication weakness (CWE‑290).
Affected Systems
Red Hat Multicluster GlobalHub version 1.8 on Enterprise Linux 9. All managed hubs that subscribe to the shared gh‑spec Kafka topic are affected, as they rely on the unverified CloudEvent source for resource deployment.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.9, indicating critical severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker gains control of any managed hub; once compromised, the attacker can leverage the shared Kafka topic to impersonate the global hub and influence all other hubs in the cluster. The attack vector is remote, via the Kafka network, and does not require privileged access beyond the compromised hub’s credentials.
OpenCVE Enrichment