Junglewise Threat Intelligence

CVE-2026-89060: Red Hat multicluster-observability-addon cross-namespace authorization bypass

CVE-2026-89060 · Severity: high · CVSS 7.7 · Published 2026-09-11

Vendors: Red Hat.

Executive brief

The multicluster-observability-addon is a component used to monitor and collect observability data across multiple Kubernetes clusters. A flaw allows users with permission to configure a managed cluster to reference monitoring resources outside their authorized namespace, potentially exposing sensitive credentials. An attacker could exploit this to steal secrets from other namespaces and exfiltrate them to a compromised cluster.

Technical details

A cross-namespace authorization flaw in multicluster-observability-addon permits users with ManagedClusterAddOn modification rights to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. The vulnerability stems from insufficient authorization checks when validating resource references, allowing an attacker to point configurations at arbitrary secrets. The attack requires prior permission to modify a managed cluster's AddOn configuration; an attacker can exploit this to exfiltrate Secrets to an attacker-controlled managed cluster. No patch status is indicated in the advisory.

Affected products

  • Red Hat multicluster-observability-addon

Timeline

  • 2026-09-11: disclosed

References