Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-72526: OpenShift Multicloud Integrations allows arbitrary code execution
CVE-2026-72526 · published 23 days ago
Summary
A vulnerability in OpenShift's multicloud integrations component allows an attacker to execute arbitrary code on managed clusters. This can happen if a tenant with permission to create applications on the hub cluster exploits the flaw. To protect your clusters, ensure proper validation and access controls are in place.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
Original advisory text
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without pro...
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta