Description
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A cross-namespace authorization flaw in multicluster-observability-addon affects log-forwarding and tracing configurations that use ClusterLogForwarder or OpenTelemetryCollector resources. An authorized user who can modify ManagedClusterAddOn configuration could reference resources in another hub namespace, potentially disclosing associated Secrets to an attacker-controlled managed cluster. A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.

Fri, 11 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster. A cross-namespace authorization flaw in multicluster-observability-addon affects log-forwarding and tracing configurations that use ClusterLogForwarder or OpenTelemetryCollector resources. An authorized user who can modify ManagedClusterAddOn configuration could reference resources in another hub namespace, potentially disclosing associated Secrets to an attacker-controlled managed cluster.

Fri, 11 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster.
Title Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
First Time appeared Redhat
Redhat acm
Weaknesses CWE-551
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T20:30:32.165Z

Reserved: 2026-09-10T18:21:30.542Z

Link: CVE-2026-89060

cve-icon Vulnrichment

Updated: 2026-09-11T16:31:52.748Z

cve-icon NVD

Status : Received

Published: 2026-09-11T05:16:38.557

Modified: 2026-09-11T21:17:56.740

Link: CVE-2026-89060

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:00:00Z

Links: CVE-2026-89060 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses