AI description
CVE-2026-72526 is a vulnerability found within the `multicloud-integrations` component, specifically affecting the Application propagation controller. This flaw arises because the controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without adequate validation. This lack of validation enables a tenant with permissions to create Applications on the hub cluster to target and influence arbitrary managed (spoke) clusters. Exploitation of this vulnerability can force ArgoCD on the targeted spoke clusters to synchronize attacker-controlled manifests, which can result in arbitrary code execution or privilege escalation on those clusters.
- Description
- A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
- Source
- secalert@redhat.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- secalert@redhat.com
- CWE-441
- Hype score
- Not currently trending
🚨 CRITICAL: Red Hat has patched two CVSS 9.9 remote code execution flaws in Red Hat Advanced Cluster Management (RHACM). Tracked as CVE-2026-72526 and CVE-2026-73268, both vulnerabilities can potentially lead to remote code execution in affected environments. Admins should h
@ThreatWire_
17 Aug 2026
1532 Impressions
5 Retweets
15 Likes
4 Bookmarks
2 Replies
0 Quotes
Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps. #RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec https://t.co/Nd7b9tj2CG
@Daily_CyberSec
17 Aug 2026
409 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes