Description
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cluster health information, belonging to other hubs in the database.
Published: 2026-08-10
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the manager component of Multicluster Global Hub, which does not properly validate the source identity of CloudEvents received on Kafka status topics, constituting a trust verification flaw (CWE‑345). When an attacker has compromised a managed hub and acquired its Kafka client certificate, they can forge or tamper with the self‑asserted source identity of events. This unauthorized control allows the attacker to insert false information or delete legitimate entries, such as compliance reports, inventory records, and cluster health data, from the shared database. The breach directly harms the integrity and availability of critical operational data and can lead to incorrect operational decisions or misrepresentation of cluster health.

Affected Systems

Red Hat Multicluster Global Hub installations are potentially impacted. No specific version range is listed, so any deployment of the product may require review.

Risk and Exploitability

Based on the description, it is inferred that the exploitation does not involve code execution but can undermine the integrity and availability of cluster‑wide monitoring data. The attack requires prior compromise of a hub to acquire its Kafka client certificate; once obtained, the attacker can exploit the lack of source identity verification to falsify or delete status data. The CVSS score of 8.5 classifies this vulnerability as High severity, yet the EPSS score is currently unavailable and it is not present in the CISA KEV catalog, implying no publicly known exploitation at this time. Organizations should evaluate the likelihood of internal compromise and the exposure of Kafka topics to mitigate this risk.

Generated by OpenCVE AI on August 10, 2026 at 20:12 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Acquire and apply any official patch or update from Red Hat addressing this identity verification issue as soon as it becomes available.
  • Apply the Red Hat‑provided workaround to mitigate the identity validation flaw until a patch is available.
  • Limit network paths to the Kafka status topic so that only properly authenticated and authorized hub instances can publish events, and block or quarantine any hub that has been compromised.
  • Implement continuous monitoring and alerting on critical data tables for unexpected deletions or anomalies, and perform regular audit reviews to detect tampering early.

Generated by OpenCVE AI on August 10, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 10 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cluster health information, belonging to other hubs in the database.
Title Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source() for leaf-hub identity in all status handlers
First Time appeared Redhat
Redhat multicluster Globalhub
Weaknesses CWE-345
CPEs cpe:/a:redhat:multicluster_globalhub
Vendors & Products Redhat
Redhat multicluster Globalhub
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}


Subscriptions

Redhat Multicluster Globalhub
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-10T16:41:53.193Z

Reserved: 2026-08-07T14:20:37.114Z

Link: CVE-2026-71576

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-10T14:38:00Z

Links: CVE-2026-71576 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T20:15:03Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity