No analysis available yet.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 12 Aug 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects. | |
| Title | Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-441 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T12:36:53.713Z
Reserved: 2026-08-11T17:40:07.970Z
Link: CVE-2026-70398
No data.
Status : Received
Published: 2026-08-12T02:16:38.060
Modified: 2026-08-12T02:16:38.060
Link: CVE-2026-70398
OpenCVE Enrichment
No data.
-
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')