CVE-2026-72526
Awaiting Analysis Awaiting Analysis - Queue

ArgoCD Arbitrary Code Execution via Application Propagation Flaw

Vulnerability report for CVE-2026-72526, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-27

Assigner: redhat-SADP

Description

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-27
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
red_hat advanced_cluster_management *-*
redhat multicloud_integrations *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a critical flaw in Red Hat Advanced Cluster Management's multicloud-integrations component. The Application propagation controller does not validate the ocm-managed-cluster annotation in Application Custom Resources. A tenant with Application creation permissions on the hub cluster can exploit this to target any managed cluster. This forces ArgoCD on spoke clusters to sync attacker-controlled manifests, enabling arbitrary code execution or privilege escalation with cluster-admin privileges.

Detection Guidance

Check for unauthorized Application CRs with the ocm-managed-cluster annotation on the hub cluster. Inspect ArgoCD logs on spoke clusters for unexpected manifest synchronizations or synchronization errors.

Impact Analysis

If you are a tenant with permissions to create Applications on the hub cluster, an attacker could exploit this to gain control over managed clusters. This could lead to unauthorized code execution, privilege escalation, or hidden malicious activities on those clusters. The impact includes potential data breaches, system compromise, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or privilege escalation, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected systems may face legal penalties, reputational damage, or loss of certification if exploited.

Mitigation Strategies

Restrict Application CR creation permissions on the hub cluster to trusted users only. Monitor ArgoCD logs on spoke clusters for suspicious activities. Apply patches or updates as soon as they become available from Red Hat.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72526. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart