Description
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.
Published: 2026-08-10
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During a ManagedClusterMigration, the Multicluster Global Hub mistakenly grants all managed hubs read access to a shared communication topic. This mis‑configured ACL allows a compromised hub to intercept and collect the sensitive bootstrap kubeconfigs that embed API‑server tokens meant for other hubs. The weakness is a failure of access control that exposes user credentials (CWE-522), leading to sensitive information leakage. Those tokens have an unusually long validity period, approximately nine and a half years, amplifying the potential damage if accessed by an attacker.

Affected Systems

The issue affects the Red Hat Multicluster Global Hub platform. Specific version details are not listed in the advisory, so any instance of the product lacking a documented patch may be vulnerable until a fixed release is issued.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate risk. The EPSS score is unavailable, so the likelihood of exploitation cannot be precisely quantified. Attackers would need to control a managed hub and trigger a ManagedClusterMigration to gain read access to the spec‑topic, after which they could capture bootstrap kubeconfigs. No KEV listing indicates that there is no known large‑scale exploitation reported.

Generated by OpenCVE AI on August 10, 2026 at 19:38 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Immediately reconfigure the Multicluster Global Hub ACL for the spec‑topic to grant read access only to the hub undergoing migration, preventing all other hubs from reading it.
  • Apply the latest Red Hat update for Multicluster Global Hub as soon as a fix is released, ensuring the vulnerability is patched.
  • Follow the Red Hat Product Security advised workaround, recognizing it may not fully meet security criteria.
  • Rotate or regenerate bootstrap kubeconfig API tokens for all managed clusters to reduce the exposure window for compromised tokens.
  • Monitor logs and cluster traffic for unusual access to bootstrap kubeconfigs and investigate any suspicious activity.

Generated by OpenCVE AI on August 10, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 10 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.
Title Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migration
First Time appeared Redhat
Redhat multicluster Globalhub
Weaknesses CWE-522
CPEs cpe:/a:redhat:multicluster_globalhub
Vendors & Products Redhat
Redhat multicluster Globalhub
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Multicluster Globalhub
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T01:59:34.075Z

Reserved: 2026-08-07T14:20:37.114Z

Link: CVE-2026-71577

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-10T14:38:00Z

Links: CVE-2026-71577 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T19:45:04Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials