ZeroHour

CVE-2026-89060

moderate

Cross-namespace secret disclosure in Red Hat multicluster-observability-addon

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

The multicluster-observability-addon component, which pushes metrics-collection configuration from a Kubernetes hub cluster (e.g., Red Hat Advanced Cluster Management for Kubernetes) out to managed clusters, fails to confine configuration-resource references to the requesting managed cluster's own namespace. As a result, a managed-cluster identity that authenticates to the hub can reference configuration resources in other namespaces, and hub Secrets referenced by those configurations are exposed to that cluster. An attacker who controls or has compromised a managed cluster can thereby read sensitive hub Secrets, consistent with the CVSS score of 7.7 (scope changed, high confidentiality impact, no integrity or availability impact; CWE-551, incorrect behavior order in handling cross-namespace references). Affected users are operators running Red Hat Advanced Cluster Management for Kubernetes or equivalent open-cluster-management deployments with the multicluster observability addon enabled. No public proof-of-concept is known, the flaw is not in CISA KEV, and there are no reports of in-the-wild exploitation.

What to do: Apply the fix per the Red Hat security advisory for multicluster-observability-addon once released (no fixed version number is provided in this data), then restart the addon agents on managed clusters. Until patched, audit which hub-cluster Secrets are referenced by observability configuration, rotate any hub Secrets that may have been delivered to less-trusted managed clusters, and review hub RBAC so managed-cluster identities cannot resolve references outside their namespace.

Affected
Red Hat / open-cluster-management multicluster-observability-addon (multicluster observability component of Red Hat Advanced Cluster Management for Kubern
Estimated exposure
moderate≈1,000–10,000 hub-cluster deployments (estimate) — The addon ships only with Red Hat ACM/OpenShift-style multicluster-observability and related open-cluster-management stacks, is an opt-in feature limited to hub clusters in enterprise multi-cluster setups, and no public install counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.

Weakness
CWE-551
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.