---
id: CVE-2026-71577
title: A flaw was found in multicluster-global-hub
summary: >-
  A flaw was found in multicluster-global-hub. During a ManagedClusterMigration,
  the system incorrectly grants all managed hubs read access to a shared
  communication topic. This allows a compromised managed hub to intercept and
  collect sen…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: Red Hat
product: multicluster-globalhub/multicluster-globalhub-rhel9-operator
affected:
  - multicluster-globalhub/multicluster-globalhub-rhel9-operator (all versions)
  - multicluster-globalhub/multicluster-globalhub-rhel9-operator (all versions)
  - multicluster-globalhub/multicluster-globalhub-rhel9-operator (all versions)
  - multicluster-globalhub/multicluster-globalhub-rhel9-operator (all versions)
patched:
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.7.3
  - multicluster_global_hub 1.8.2
published: '2026-08-10'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T18:18:31.503'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71577'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:67516'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:67842'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68515'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71597'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-71577'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2512514'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-71577.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-71577'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71577'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-11T01:59:24.928197Z'
epss: 0.00404
epssPercentile: 0.31899
ingestedAt: '2026-09-21T11:35:54.433Z'
---

## Overview

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:67516** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67516)
- **RHSA-2026:67842** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67842)
- **RHSA-2026:68515** · Red Hat · fixed in: Multicluster Global Hub 1.8.2 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68515)
- **RHSA-2026:71597** · Red Hat · fixed in: Multicluster Global Hub 1.5.8 · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71597)
