Status: UPDATED
| Advisory ID: CVE-2026-89060
Key Details
| CVE | CVE-2026-89060 |
| CVSS Score / Version | 7.7 (High) / CVSS v3.1 |
| Updated | 2026-09-21 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is none; availability impact is none. |
| Affected products | Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16, and Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17 |
| Classified as | CWE-551 (Incorrect Behavior Order: Authorization Before Parsing and Canonicalization) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References