[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#cross-namespace authorization flaw

newsHIGH 7.7

CVE-2026-89060: Cross-Namespace Authorization Flaw in multicluster-observability-addon

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster's ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace, potentially leading to sensitive information disclosure. This vulnerability has a CVSS score of 7.7 and is considered HIGH severity. Affected products include Red Hat Advanced Cluster Management for Kubernetes 2 and multicluster-observability-addon.

Sep 12, 20261 source