Impact
The flaw lies in the manager component of Multicluster Global Hub, which does not properly validate the source identity of CloudEvents received on Kafka status topics, constituting a trust verification flaw (CWE‑345). When an attacker has compromised a managed hub and acquired its Kafka client certificate, they can forge or tamper with the self‑asserted source identity of events. This unauthorized control allows the attacker to insert false information or delete legitimate entries, such as compliance reports, inventory records, and cluster health data, from the shared database. The breach directly harms the integrity and availability of critical operational data and can lead to incorrect operational decisions or misrepresentation of cluster health.
Affected Systems
Red Hat Multicluster Global Hub installations are potentially impacted. No specific version range is listed, so any deployment of the product may require review.
Risk and Exploitability
Based on the description, it is inferred that the exploitation does not involve code execution but can undermine the integrity and availability of cluster‑wide monitoring data. The attack requires prior compromise of a hub to acquire its Kafka client certificate; once obtained, the attacker can exploit the lack of source identity verification to falsify or delete status data. The CVSS score of 8.5 classifies this vulnerability as High severity, yet the EPSS score is currently unavailable and it is not present in the CISA KEV catalog, implying no publicly known exploitation at this time. Organizations should evaluate the likelihood of internal compromise and the exposure of Kafka topics to mitigate this risk.
OpenCVE Enrichment