Impact
The multicloud-integrations component of Red Hat Advanced Cluster Management for Kubernetes processes the ocm‑managed‑cluster annotation of an Application Custom Resource without proper validation. A tenant with permission to create Applications on the hub cluster can supply an arbitrary cluster identifier. The controller then propagates this annotation to the target spoke cluster’s ArgoCD instance, causing it to synchronize attacker‑controlled manifests and potentially execute arbitrary code or elevate privileges on that cluster.
Affected Systems
This issue affects Red Hat Advanced Cluster Management for Kubernetes 2. No specific version range is listed in the advisory; organizations should consult the official Red Hat security advisory for the latest impacted releases.
Risk and Exploitability
The CVSS score of 9.9 designates the vulnerability as critical, but the EPSS score is below 1 %, indicating a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires actions performed from the hub cluster: a tenant with sufficient privileges to create Application resources and the ability to specify an arbitrary cluster via the unvalidated annotation. From that interior position, the attacker can trigger ArgoCD syncs that deploy malicious manifests onto the spoke cluster, giving the attacker control over the managed cluster. The attack vector is inferred to be internal to the hub cluster and relies on privileged access rather than external network exposure.
OpenCVE Enrichment