Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-namespace authorization flaw in multicluster-observability-addon affects log-forwarding and tracing configurations that use ClusterLogForwarder or OpenTelemetryCollector resources. An authorized user who can modify ManagedClusterAddOn configuration could reference resources in another hub namespace, potentially disclosing associated Secrets to an attacker-controlled managed cluster. | A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster. |
Fri, 11 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster. | A cross-namespace authorization flaw in multicluster-observability-addon affects log-forwarding and tracing configurations that use ClusterLogForwarder or OpenTelemetryCollector resources. An authorized user who can modify ManagedClusterAddOn configuration could reference resources in another hub namespace, potentially disclosing associated Secrets to an attacker-controlled managed cluster. |
Fri, 11 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster. | |
| Title | Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-551 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-11T20:30:32.165Z
Reserved: 2026-09-10T18:21:30.542Z
Link: CVE-2026-89060
No data.
Status : Received
Published: 2026-09-11T05:16:38.557
Modified: 2026-09-11T21:17:56.740
Link: CVE-2026-89060
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:30:08Z