Skip to content
Red HatCVE-2026-89060

Red Hat, Inc.: CVE: user could modify a managed cluster’s ManagedClusterAddOn

High7.7CVE-2026-89060 · Published Sep 11, 2026 · updated Sep 21, 2026

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat, Inc.: CVE records (CNA)
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux 10: denial of service
Medium6.2Sep 11
Red Hat Ceph Storage 4: buffer overflow
Medium6.1Sep 11
Red Hat Dynamic Client Registration service of Keycloak: information disclosure
Medium4.9Sep 11
A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost
Medium5.5Sep 11
Red Hat GStreamer: integer overflow
Medium4.4Sep 11
Red Hat admin backend of gvfs: race condition
High7.0Sep 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.