CVE-2026-89060: Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Deployments using multicluster-observability-addon are exposed where a managed-cluster identity can supply configuration references. The impact is disclosure of sensitive Secrets from the hub to an attacker-controlled managed cluster.
What level of access does an attacker need?
An attacker needs privileges associated with a managed-cluster identity. The attack can be performed over the network without user interaction, and the issue has low attack complexity.
What is the security impact if exploitation succeeds?
A managed-cluster identity may reference configuration resources outside its designated namespace and obtain sensitive hub Secrets. The reported impact is high confidentiality impact, with no stated integrity or availability impact.