Information Disclosure Vulnerability in multicluster-observability-addon
A configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.
CVE search metadata
CVE search record: CVE-2026-89060. Severity: high. CVSS: 7.7. KEV: no. Product: multicluster-observability-addon. Brief: Information Disclosure Vulnerability in multicluster-observability-addon. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-89060/
The multicluster-observability-addon contains a configuration reference flaw identified as CVE-2026-89060. This vulnerability allows an authenticated actor with control over a managed-cluster identity to bypass standard Kubernetes namespace isolation. Specifically, the addon fails to properly validate the scope of configuration resource requests, permitting the managed identity to reference resources located outside its assigned namespace. If exploited, an attacker can leverage this misconfiguration to gain unauthorized access to and disclose sensitive Secrets stored within the hub cluster. This vulnerability poses a significant risk to multi-cluster environments managed via Red Hat Advanced Cluster Management, as the compromise of hub-level secrets can lead to full administrative control over the management infrastructure or lateral movement across the fleet of clusters.
Impact
Successful exploitation allows for the unauthorized disclosure of sensitive hub-level Secrets, potentially leading to the compromise of management credentials, API tokens, or encryption keys. This affects organizations utilizing the multicluster-observability-addon in a hub-and-spoke cluster architecture, enabling attackers to escalate privileges from a single managed cluster to the central management hub.
Recommendation
- Audit cluster logs for unauthorized access attempts targeting secret resources originating from managed-cluster service accounts.
- Apply security patches or updates provided by the vendor for the multicluster-observability-addon to enforce strict namespace isolation for managed identities.
- Review RBAC and namespace access controls for all managed-cluster identities to limit the blast radius of potential configuration reference bypasses.
Immediate actions
Inventory all managed clusters utilizing the multicluster-observability-addon and verify patch status.
Mitigations
Upgrade multicluster-observability-addon to the vendor-recommended secure version.
CVE-2026-89060