CVE-2026-71576
Received Received - Intake

Improper Source Identity Validation in multicluster-global-hub

Vulnerability report for CVE-2026-71576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cluster health information, belonging to other hubs in the database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat multicluster-global-hub *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the multicluster-global-hub manager component. It fails to properly validate the source identity of incoming CloudEvents on Kafka status topics. An attacker who compromises a managed hub and steals its Kafka client certificate can falsify the source identity. This lets them alter or delete important data like compliance records, inventory details, and cluster health information for other hubs in the database.

Impact Analysis

If you use multicluster-global-hub, an attacker could manipulate your system's data integrity. They might falsify compliance reports, hide inventory issues, or corrupt cluster health status. This could lead to incorrect operational decisions, security gaps, or compliance violations without your knowledge.

Compliance Impact

This vulnerability could undermine compliance with GDPR, HIPAA, and similar regulations. Falsified compliance or inventory data might result in inaccurate reporting, leading to potential violations. Organizations relying on this system for audits could face legal or regulatory penalties due to compromised data integrity.

Mitigation Strategies

Immediately update multicluster-global-hub to the latest patched version to address the improper CloudEvents validation flaw. Restrict network access to Kafka status topics and revoke compromised Kafka client certificates. Monitor database entries for unauthorized modifications to compliance, inventory, or cluster health data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart