CVE-2026-70398: Red Hat Advanced Cluster Management For Kubernetes 2.11
Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787260689 (fixed in 1787260689)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787259106 (fixed in 1787259106)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787183407 (fixed in 1787183407)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238604 (fixed in 1787238604)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787252179 (fixed in 1787252179)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787243221 (fixed in 1787243221)
Published 2026-08-12. Last modified 2026-08-27.