multicluster-globalhub/multicluster-globalhub-manager-rhel9 vulnerabilities
CVEs whose affected-version data names the multicluster-globalhub/multicluster-globalhub-manager-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-66792Critical· 9.9A flaw was found in the multicloud-operators-subscription component
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…
▾ MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.69%via NVD
CVE-2026-71576High· 8.5A flaw was found in multicluster-global-hub
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka clien…
▾ TwilightRed Hat · multicluster-globalhub/multicluster-globalhub-manager-rhel9EPSS 0.23%via NVD