Description
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A cross-namespace authorization flaw in multicluster-observability-addon affects log-forwarding and tracing configurations that use ClusterLogForwarder or OpenTelemetryCollector resources. An authorized user who can modify ManagedClusterAddOn configuration could reference resources in another hub namespace, potentially disclosing associated Secrets to an attacker-controlled managed cluster. A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster. A cross-namespace authorization flaw in multicluster-observability-addon affects log-forwarding and tracing configurations that use ClusterLogForwarder or OpenTelemetryCollector resources. An authorized user who can modify ManagedClusterAddOn configuration could reference resources in another hub namespace, potentially disclosing associated Secrets to an attacker-controlled managed cluster.

Fri, 11 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster.
Title Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
First Time appeared Redhat
Redhat acm
Weaknesses CWE-551
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T14:22:04.612Z

Reserved: 2026-09-10T18:21:30.542Z

Link: CVE-2026-89060

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T05:16:38.557

Modified: 2026-09-11T15:17:08.503

Link: CVE-2026-89060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses