{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/multicloud-integrations/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-72526"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["multicloud-integrations"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-72526 is a critical vulnerability identified in the multicloud-integrations component, specifically within the Application propagation controller. The flaw arises from the improper validation of the 'ocm-managed-cluster' annotation when processing Application Custom Resources (CRs). An authenticated tenant who possesses sufficient permissions to create Applications on a hub cluster can manipulate this annotation to direct the propagation of manifests to unauthorized managed clusters.\u003c/p\u003e\n\u003cp\u003eBy weaponizing this, an attacker can force the ArgoCD instance on the targeted spoke clusters to synchronize and apply malicious manifests. This technique allows for arbitrary code execution and potential privilege escalation within the context of the managed cluster's service accounts. This vulnerability represents a significant risk in multicloud environments where multitenancy is enforced at the hub, as the impact propagates downstream to spoke infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a restricted tenant to break out of their intended cluster isolation and execute arbitrary code on managed (spoke) clusters. This cross-cluster compromise can lead to full cluster takeover, exfiltration of cluster secrets, and disruption of managed services across the multicloud infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all users and service accounts with permissions to create or update Application Custom Resources (CRs) on the hub cluster and review their authorization scopes.\u003c/li\u003e\n\u003cli\u003eImplement strict Kubernetes Admission Control (such as OPA Gatekeeper or Kyverno) to validate the 'ocm-managed-cluster' annotation against a known-good allowlist of clusters for specific tenants.\u003c/li\u003e\n\u003cli\u003eAudit Application CRs on the hub cluster for unexpected 'ocm-managed-cluster' values or references to managed clusters outside of a tenant's authorized scope.\u003c/li\u003e\n\u003cli\u003eMonitor ArgoCD synchronization logs on managed clusters for unexpected or unauthorized manifest sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T07:11:02Z","date_published":"2026-08-12T07:11:02Z","id":"https://feed.craftedsignal.io/briefs/2026-08-12-cve-2026-72526/","summary":"An authenticated tenant with Application creation permissions can exploit an improper input validation flaw in the multicloud-integrations Application propagation controller to achieve remote code execution on managed clusters.","title":"CVE-2026-72526: Improper Validation in Multicloud-Integrations Component","url":"https://feed.craftedsignal.io/briefs/2026-08-12-cve-2026-72526/"}],"language":"en","title":"CraftedSignal Threat Feed - Multicloud-Integrations","version":"https://jsonfeed.org/version/1.1"}