CVE-2026-70398
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Red Hat Advanced Cluster Management

Vulnerability report for CVE-2026-70398, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-27

Assigner: redhat-SADP

Description

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-27
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
red_hat advanced_cluster_management to 3.0.0 (exc)
red_hat multicloud_integrations *
red_hat advanced_cluster_management *
argocd appprojects *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Red Hat Advanced Cluster Management (RHACM) affecting the multicloud-integrations component. An authenticated tenant can exploit the GitOpsCluster controller to redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This allows unauthorized access to critical information and bypasses security policies in ArgoCD AppProjects.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized namespace access or token redirection in RHACM. Monitor GitOpsCluster controller logs for suspicious secret writes to unexpected namespaces. Review ArgoCD AppProject policies for bypass attempts. No specific commands are provided in the available resources.

Impact Analysis

An attacker could gain access to sensitive cluster tokens, leading to unauthorized disclosure of critical information. They could also bypass security policies within ArgoCD AppProjects, potentially escalating privileges and compromising cluster integrity.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It may result in non-compliance due to potential data breaches and unauthorized access to protected health or personal information.

Mitigation Strategies

No immediate mitigation steps are currently available from Red Hat. The vulnerability lacks effective fixes meeting Red Hat's criteria for deployment stability and usability. Monitor Red Hat's official advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70398. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart