A flaw in the multicloud-integrations component allows authenticated tenants to perform arbitrary code execution or privilege escalation on managed cl...
Description
A flaw in the multicloud-integrations component allows authenticated tenants to perform arbitrary code execution or privilege escalation on managed clusters via improper annotation validation.
AI Analyst Comment
Remediation
Update Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Red Hat
PRODUCT: Red Hat Advanced Cluster Management for Kubernetes
AFFECTED_VERSIONS: Red Hat Advanced Cluster Management for Kubernetes 2
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A flaw in the multicloud-integrations component allows authenticated tenants to perform arbitrary code execution or privilege escalation on managed clusters via improper annotation validation.
Executive Summary:
A critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2 allows authenticated tenants to escalate privileges to cluster-admin on connected spoke clusters.
Vulnerability Details
CVE-ID: CVE-2026-72526
Affected Software: Red Hat Advanced Cluster Management for Kubernetes
Affected Versions: Red Hat Advanced Cluster Management for Kubernetes 2
Vulnerability: This vulnerability involves a confused deputy mechanism where improper annotation validation allows an authenticated user with Application creation permissions on the hub cluster to execute arbitrary code or gain elevated privileges on managed spoke clusters.
Business Impact
The vulnerability carries a CVSS score of 9.9, indicating an extreme risk to the integrity and availability of the entire container orchestration environment. Successful exploitation allows a tenant to bypass security boundaries, resulting in full unauthorized control over managed clusters, which could lead to massive data exfiltration, lateral movement, or complete system disruption.
Remediation Plan
Immediate Action: Update Red Hat Advanced Cluster Management for Kubernetes 2 to the latest available version provided by the vendor.
Proactive Monitoring: Monitor hub and spoke cluster access logs for anomalous annotation activity or unauthorized attempts to perform administrative actions on managed clusters.
Compensating Controls: Restrict Application creation permissions to highly trusted users until the patch can be applied, and ensure RBAC policies are strictly enforced across the hub cluster.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 12, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the potential for cross-cluster privilege escalation.
Analyst Recommendation
Given the critical CVSS score of 9.9 and the potential for total compromise of connected infrastructure, this vulnerability requires immediate attention. Security teams should prioritize patching the hub cluster and reviewing existing RBAC configurations to limit the blast radius of any potentially compromised accounts.