Executive brief
Red Hat Multicluster Global Hub is a Kubernetes management platform that allows organizations to manage multiple hub clusters from a central location. A flaw during cluster migrations incorrectly grants all managed hubs read access to shared communication channels, allowing a compromised hub to steal long-lived API tokens intended for other clusters. These tokens remain valid for approximately 10 years, providing attackers with sustained unauthorized access to other managed Kubernetes environments.
Technical details
The vulnerability is an access control flaw triggered during ManagedClusterMigration operations. The system improperly configures permissions on a shared communication topic, granting read access to all managed hubs instead of limiting access to intended recipients. An attacker controlling a compromised managed hub can intercept bootstrap kubeconfigs transiting the shared topic, extracting API server tokens with extended validity (~9.86 years). This enables unauthorized access and information disclosure across managed clusters. The vulnerability requires a managed hub to be compromised, but no network-level or authentication-level bypass is indicated—the flaw is in the migration logic itself. Patches are available in Multicluster Global Hub 1.4.9 and later.
Affected products
- Red Hat Multicluster Global Hub before 1.4.9
Timeline
- 2026-08-10: disclosed
- 2026-09-15: advisory: RHSA-2026:67516 published as security advisory
- 2026-09-15: patched: Fix available in Multicluster Global Hub 1.4.9