Red HatCVE-2026-89060
Red Hat, Inc.: CVE: user could modify a managed cluster’s ManagedClusterAddOn
High7.7CVE-2026-89060 · Published Sep 11, 2026 · updated Sep 21, 2026
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat, Inc.: CVE records (CNA) Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-551
- www.cve.org/CVERecord?id=CVE-2026-89060
- nvd.nist.gov/vuln/detail/CVE-2026-89060
- access.redhat.com/errata/RHSA-2026:67539
- access.redhat.com/errata/RHSA-2026:67540
- access.redhat.com/errata/RHSA-2026:67541
- access.redhat.com/errata/RHSA-2026:67542
- access.redhat.com/errata/RHSA-2026:67543
- access.redhat.com/security/cve/CVE-2026-89060
- bugzilla.redhat.com/show_bug.cgi?id=2531596
- github.com/stolostron/multicluster-observability-addon/pull/644
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Red Hat Enterprise Linux 10: denial of service | Medium6.2 | No fix yet |
| Sep 11 | Red Hat Ceph Storage 4: buffer overflow | Medium6.1 | No fix yet |
| Sep 11 | Red Hat Dynamic Client Registration service of Keycloak: information disclosure | Medium4.9 | No fix yet |
| Sep 11 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost | Medium5.5 | No fix yet |
| Sep 11 | Red Hat GStreamer: integer overflow | Medium4.4 | No fix yet |
| Sep 10 | Red Hat admin backend of gvfs: race condition | High7.0 | 1.62.0+2 more |