Executive brief
Red Hat multicluster-engine manages multiple Kubernetes clusters across cloud and data center environments. An attacker with cluster permissions and knowledge of previous credential values can bypass authorization controls to intercept newly rotated provider credentials by manipulating labels, exposing sensitive access credentials that should be protected.
Technical details
The vulnerability is an authorization bypass in the provider-credential-controller component of multicluster-engine. An authenticated attacker with specific permissions on the hub cluster can manipulate `copiedFrom` labels to intercept newly rotated provider credentials, bypassing normal authorization checks. The attack requires prior knowledge of a credential value and specific cluster permissions. Exploitation leads to unauthorized information disclosure of sensitive credentials. A patch is available in MCE v2.11.6 as indicated by the RHSA-2026:59556 security advisory.
Affected products
- Red Hat multicluster-engine for Kubernetes prior to 2.11.6
Timeline
- 2026-08-12: disclosed
- 2026-08-25: advisory: Red Hat Security Advisory RHSA-2026:59556 issued for multicluster engine v2.11.6