Junglewise Threat Intelligence

CVE-2026-72526: Red Hat Advanced Cluster Management input validation bypass in multicloud-integrations

CVE-2026-72526 · Severity: critical · CVSS 9.9 · Published 2026-08-12

Vendors: Red Hat.

Executive brief

Red Hat Advanced Cluster Management is a multi-cluster management platform that oversees Kubernetes clusters and applications across hybrid cloud environments. A flaw in the Application propagation controller fails to validate user input, allowing a tenant with permission to create Applications to target arbitrary managed clusters and force malicious manifest synchronization, resulting in arbitrary code execution on those clusters.

Technical details

The vulnerability is an input validation flaw in the Application propagation controller component of the multicloud-integrations service. The controller processes the `ocm-managed-cluster` annotation from Application Custom Resources (CR) without proper validation of the cluster target. A tenant with permissions to create Applications on the hub cluster can exploit this to specify arbitrary managed clusters as targets. This forces ArgoCD instances on spoke clusters to synchronize attacker-controlled manifests, enabling arbitrary code execution or privilege escalation. The flaw is inherently network-reachable and requires only valid Application creation permissions (no special escalation required).

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes 2.17.1 and earlier

Timeline

  • 2026-08-12: disclosed
  • 2026-08-26: advisory
  • 2026-08-26: patched: Fixed in ACM 2.17.1 security update via RHSA-2026:60386

References