Executive brief
Red Hat Advanced Cluster Management (RHACM) is a Kubernetes platform that manages multiple clusters across hybrid cloud environments from a central console. A flaw in its multicloud-integrations component allows authenticated users to steal sensitive security tokens from secure storage locations, compromising cluster security and enabling unauthorized access to critical infrastructure. An attacker with tenant access could extract bearer tokens and bypass ArgoCD security policies, leading to cluster takeover and sensitive data exposure.
Technical details
This vulnerability exists in the multicloud-integrations component of RHACM and involves improper token handling in the GitOpsCluster controller. An authenticated tenant can manipulate the controller to redirect spoke cluster bearer tokens from their intended secure storage to a namespace under the attacker's control. The attack requires valid tenant authentication but no additional user interaction. Successful exploitation results in disclosure of critical authentication credentials and circumvention of ArgoCD AppProject security policies, potentially allowing lateral movement and cluster compromise. The vulnerability has been addressed in RHACM v2.17.1 (RHSA-2026:60386).
Affected products
- Red Hat Advanced Cluster Management for Kubernetes before 2.17.1
Timeline
- 2026-08-12: disclosed
- 2026-08-26: patched: Fix released in RHSA-2026:60386 with RHACM v2.17.1