CVE-2026-71576: Red Hat Multicluster Global Hub 1.4.9
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cluster health information, belonging to other hubs in the database.
Affected products
- Red Hat Multicluster Global Hub 1.4.9: before 1788355599 (fixed in 1788355599)
- Red Hat Multicluster Global Hub 1.5.8: before 1789515288 (fixed in 1789515288)
- Red Hat Multicluster Global Hub 1.6.6: before 1790086176 (fixed in 1790086176)
- Red Hat Multicluster Global Hub 1.7.3: before 1788377424 (fixed in 1788377424)
- Red Hat Multicluster Global Hub 1.8.2: before 1788359454 (fixed in 1788359454)
Published 2026-08-10. Last modified 2026-09-29.