REDHAT-BUG-2514227: High severity Red Hat Red Hat Advanced Cluster Management (RHACM) vulnerability
A flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM). The Application propagation controller takes the tenant-controlled ocm-managed-cluster annotation verbatim from an Application CR and uses it as the ManifestWork namespace without authorization checks. The only validation is a bare existence check on the target ManagedCluster. A tenant with Application create permissions in any hub namespace can generate ManifestWorks targeting arbitrary managed clusters, resulting in spoke cluster-admin ArgoCD syncing attacker-controlled manifests.
Upstream repo: https://github.com/stolostron/multicloud-integrations Audited commit: d88a168 Jira tracker: ACM-38643
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2514227?
The severity of REDHAT-BUG-2514227 is rated as high with a score of 7.
How do I fix REDHAT-BUG-2514227?
To resolve REDHAT-BUG-2514227, ensure that proper authorization checks are added when handling tenant-controlled ocm-managed-cluster annotations.
What is the main issue described in REDHAT-BUG-2514227?
The main issue in REDHAT-BUG-2514227 is that the Application propagation controller uses tenant-controlled annotations without proper authorization, potentially leading to insecure namespace management.
Which component is affected by REDHAT-BUG-2514227?
The multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM) is affected by REDHAT-BUG-2514227.
When was REDHAT-BUG-2514227 published?
REDHAT-BUG-2514227 was published on August 11, 2026.