<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:redhat:multicluster-Observability-Addon:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aredhatmulticluster-observability-addon/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 11 Sep 2026 07:11:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aredhatmulticluster-observability-addon/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in multicluster-observability-addon</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-89060/</link><pubDate>Fri, 11 Sep 2026 07:11:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-89060/</guid><description>A configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.</description><content:encoded><![CDATA[<p>The multicluster-observability-addon contains a configuration reference flaw identified as CVE-2026-89060. This vulnerability allows an authenticated actor with control over a managed-cluster identity to bypass standard Kubernetes namespace isolation. Specifically, the addon fails to properly validate the scope of configuration resource requests, permitting the managed identity to reference resources located outside its assigned namespace. If exploited, an attacker can leverage this misconfiguration to gain unauthorized access to and disclose sensitive Secrets stored within the hub cluster. This vulnerability poses a significant risk to multi-cluster environments managed via Red Hat Advanced Cluster Management, as the compromise of hub-level secrets can lead to full administrative control over the management infrastructure or lateral movement across the fleet of clusters.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized disclosure of sensitive hub-level Secrets, potentially leading to the compromise of management credentials, API tokens, or encryption keys. This affects organizations utilizing the multicluster-observability-addon in a hub-and-spoke cluster architecture, enabling attackers to escalate privileges from a single managed cluster to the central management hub.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit cluster logs for unauthorized access attempts targeting secret resources originating from managed-cluster service accounts.</li>
<li>Apply security patches or updates provided by the vendor for the multicluster-observability-addon to enforce strict namespace isolation for managed identities.</li>
<li>Review RBAC and namespace access controls for all managed-cluster identities to limit the blast radius of potential configuration reference bypasses.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-native</category><category>kubernetes</category></item></channel></rss>