CVE-2026-71577: Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migration
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71577?
CVE-2026-71577 has a medium severity score of 6.3.
How do I fix CVE-2026-71577?
To mitigate CVE-2026-71577, ensure that access control settings are configured to restrict read access to the shared communication topic during ManagedClusterMigration.
What are the potential impacts of CVE-2026-71577?
CVE-2026-71577 could allow a compromised managed hub to intercept sensitive bootstrap kubeconfigs, potentially exposing API server tokens.
When was CVE-2026-71577 published?
CVE-2026-71577 was published on August 10, 2026.
What component is affected by CVE-2026-71577?
CVE-2026-71577 affects the multicluster-global-hub component.