CVE-2026-72526: Red Hat Advanced Cluster Management For Kubernetes 2.11
Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787260689 (fixed in 1787260689)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787259106 (fixed in 1787259106)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787183407 (fixed in 1787183407)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238604 (fixed in 1787238604)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787252179 (fixed in 1787252179)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787243221 (fixed in 1787243221)
Published 2026-08-12. Last modified 2026-08-27.