Description
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
Published: 2026-08-12
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The multicloud-integrations component of Red Hat Advanced Cluster Management for Kubernetes processes the ocm‑managed‑cluster annotation of an Application Custom Resource without proper validation. A tenant with permission to create Applications on the hub cluster can supply an arbitrary cluster identifier. The controller then propagates this annotation to the target spoke cluster’s ArgoCD instance, causing it to synchronize attacker‑controlled manifests and potentially execute arbitrary code or elevate privileges on that cluster.

Affected Systems

This issue affects Red Hat Advanced Cluster Management for Kubernetes 2. No specific version range is listed in the advisory; organizations should consult the official Red Hat security advisory for the latest impacted releases.

Risk and Exploitability

The CVSS score of 9.9 designates the vulnerability as critical, but the EPSS score is below 1 %, indicating a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires actions performed from the hub cluster: a tenant with sufficient privileges to create Application resources and the ability to specify an arbitrary cluster via the unvalidated annotation. From that interior position, the attacker can trigger ArgoCD syncs that deploy malicious manifests onto the spoke cluster, giving the attacker control over the managed cluster. The attack vector is inferred to be internal to the hub cluster and relies on privileged access rather than external network exposure.

Generated by OpenCVE AI on August 12, 2026 at 15:23 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Restrict hub‑side tenant permissions to create Applications only for intended clusters and disallow arbitrary use of the ocm‑managed‑cluster annotation by trusted users.
  • Reconfigure the multicloud‑integrations deployment to validate or whitelist the ocm‑managed‑cluster annotation before propagating it to spoke clusters.
  • Monitor ArgoCD synchronization events on spoke clusters for unexpected manifest changes and consider network segmentation or firewall rules to isolate ArgoCD instances.
  • No workaround is available from Red Hat; rely on official patch once released.

Generated by OpenCVE AI on August 12, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.16::el9
References

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2 cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.17::el9
References

Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Wed, 12 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
Title Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation
First Time appeared Redhat
Redhat acm
Weaknesses CWE-441
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-27T02:16:53.946Z

Reserved: 2026-08-11T17:40:07.967Z

Link: CVE-2026-72526

cve-icon Vulnrichment

Updated: 2026-08-12T12:38:08.270Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T02:16:38.200

Modified: 2026-08-27T04:16:49.017

Link: CVE-2026-72526

cve-icon Redhat

Severity : Critical

Publid Date: 2026-08-11T00:00:00Z

Links: CVE-2026-72526 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:20:31Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')