Executive brief
A flaw in the cluster-proxy-addon component of Red Hat's Multicluster Engine for Kubernetes allows unauthenticated attackers to bypass security controls and access internal services across managed clusters. By manipulating URL paths, an attacker can proxy requests to protected services without authorization, potentially exposing sensitive data or enabling further compromise of the entire cluster environment.
Technical details
This is an authentication and authorization bypass vulnerability in the cluster-proxy-addon component of Multicluster Engine for Kubernetes. The vulnerability allows unauthenticated attackers who can reach the user-facing route to bypass authentication checks by manipulating URL path segments. An attacker can craft requests that proxy to arbitrary services across any managed cluster without proper authorization validation. The attack requires network access to the exposed route but no prior authentication. This enables unauthorized access to internal Kubernetes services that should be protected, with potential impact including information disclosure and lateral movement within the cluster infrastructure.
Affected products
- Red Hat Multicluster Engine for Kubernetes 2.11.6 and earlier
Timeline
- 2026-08-19: disclosed
- 2026-08-25: advisory: Red Hat Security Advisory RHSA-2026:59556 published