Vulnerability intelligence
CVE-2026-72526
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
CVSS Score
9.9
Critical
EPSS — Exploit Probability
0.7%
Riskier than 51% of all CVEs · checked 2026-09-28
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 17, 2026 · latest Aug 17, 2026
Coverage timeline
-
Red Hat fixes critical RCE flaws in Advanced Cluster Managementsecurityonline.info · Aug 17, 2026