Red HatCVE-2026-71576
Red Hat multicluster-global-hub. The manager: insufficient authenticity check
High8.5CVE-2026-71576 · Published Aug 10, 2026 · updated Sep 24, 2026
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cluster health information, belonging to other hubs in the database.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-345
- www.cve.org/CVERecord?id=CVE-2026-71576
- nvd.nist.gov/vuln/detail/CVE-2026-71576
- access.redhat.com/errata/RHSA-2026:67516
- access.redhat.com/errata/RHSA-2026:67842
- access.redhat.com/errata/RHSA-2026:68515
- access.redhat.com/errata/RHSA-2026:71597
- access.redhat.com/security/cve/CVE-2026-71576
- bugzilla.redhat.com/show_bug.cgi?id=2512513
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux 10: privilege escalation | High7.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |