CVE-2026-71577: Red Hat Multicluster Global Hub 1.4.9

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.

Affected products

  • Red Hat Multicluster Global Hub 1.4.9: before 1788355417 (fixed in 1788355417)
  • Red Hat Multicluster Global Hub 1.5.8: before 1789478830 (fixed in 1789478830)
  • Red Hat Multicluster Global Hub 1.6.6: before 1790085268 (fixed in 1790085268)
  • Red Hat Multicluster Global Hub 1.7.3: before 1788372439 (fixed in 1788372439)
  • Red Hat Multicluster Global Hub 1.8.2: before 1788359461 (fixed in 1788359461); before 1790638386 (fixed in 1790638386)

Published 2026-08-10. Last modified 2026-09-29.