Executive brief
Red Hat multicluster engine is a centralized management platform for Kubernetes clusters deployed across data centers and clouds. A flaw in the clusterclaims-controller allows tenants with basic permissions to delete any managed cluster—including the hub cluster or clusters belonging to other tenants—by manipulating resource namespace fields. An attacker could disrupt operations and cause widespread service outages across multiple clusters.
Technical details
The vulnerability is an authorization bypass in the clusterclaims-controller component of multicluster engine. A standard tenant can exploit missing ownership checks in the ClusterClaim handler by manipulating the `spec.namespace` field to reference any ManagedCluster resource. This allows unauthorized deletion of managed clusters, including the local-cluster hub and clusters owned by other tenants, leading to denial of service. The flaw affects multicluster engine v2.11.6 and is fixed in updated container images released in RHSA-2026:59556.
Affected products
- Red Hat multicluster engine for Kubernetes v2.11.6 and earlier
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: RHSA-2026:59556 released with security update