Junglewise Threat Intelligence

CVE-2026-71576: Red Hat Multicluster Global Hub authentication bypass in Kafka CloudEvents

CVE-2026-71576 · Severity: high · CVSS 8.5 · Published 2026-08-10

Technologies: Red Hat Multicluster Global Hub. Vendors: Red Hat.

Executive brief

Red Hat Multicluster Global Hub is a management platform that aggregates and controls multiple Kubernetes clusters across organizations. The manager component fails to properly verify the identity of incoming messages on Kafka, allowing an attacker who has compromised one cluster and obtained its certificate to forge messages and corrupt critical data (compliance status, inventory, cluster health) across other managed clusters in the system.

Technical details

The vulnerability is an authentication bypass in the manager component's validation of CloudEvents received from Kafka status topics. The root cause is improper verification of source identity claims in incoming messages, which are self-asserted rather than cryptographically verified. An attacker who has compromised a managed hub and obtained its Kafka client certificate can manipulate the source identity field to impersonate other hubs, sending malicious CloudEvents to the manager. This allows arbitrary modification or deletion of compliance, inventory, and cluster health data in the database. The attack requires prior compromise of a managed hub to obtain valid Kafka credentials, limiting the immediate attack surface. Patches are available in Multicluster Global Hub 1.4.9 and later.

Affected products

  • Red Hat Multicluster Global Hub before 1.4.9

Timeline

  • 2026-08-10: disclosed
  • 2026-09-15: patched: Fixed in Multicluster Global Hub 1.4.9 (RHSA-2026:67516)

References

Related threats