CVE-2026-72526

Published Aug 12, 2026

Last updated 6 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-72526 is a vulnerability found within the `multicloud-integrations` component, specifically affecting the Application propagation controller. This flaw arises because the controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without adequate validation. This lack of validation enables a tenant with permissions to create Applications on the hub cluster to target and influence arbitrary managed (spoke) clusters. Exploitation of this vulnerability can force ArgoCD on the targeted spoke clusters to synchronize attacker-controlled manifests, which can result in arbitrary code execution or privilege escalation on those clusters.

Description
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
Source
secalert@redhat.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secalert@redhat.com
CWE-441

Social media

Hype score
Not currently trending