CVE-2026-71577
Received Received - Intake

Privilege Escalation in multicluster-global-hub via Topic Access

Vulnerability report for CVE-2026-71577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat multicluster-global-hub *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in multicluster-global-hub where during a ManagedClusterMigration, all managed hubs are incorrectly granted read access to a shared communication topic. This allows a compromised managed hub to intercept sensitive bootstrap kubeconfigs containing API server tokens meant for other hubs. These tokens have a long validity period of about 9.86 years, increasing the risk of unauthorized access and data exposure across managed clusters.

Impact Analysis

If exploited, this vulnerability could allow attackers to gain unauthorized access to your cluster's API server using intercepted tokens. This may lead to data breaches, unauthorized operations, or further lateral movement within your infrastructure. The long token validity exacerbates the risk, as compromised tokens remain usable for nearly a decade.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized data access and potential data breaches. GDPR requires protecting personal data, while HIPAA mandates safeguarding health information. A breach could result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately revoke all exposed bootstrap kubeconfig tokens and regenerate new ones with shorter validity periods. Audit all managed hubs for unauthorized access to the shared communication topic and restrict read permissions to only necessary hubs. Review and update the ManagedClusterMigration process to prevent improper access grants.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart