CVE-2026-72526 – Red Hat Advanced Cluster Management for Kubernetes 2

CVSS 9.9 CRITICAL Critical - Same Day Deployment

“Broken trust boundaries can turn tenant access into cluster-wide control, code execution, and exposure of critical credentials.”

Red Hat Advanced Cluster Management for Kubernetes 2 is affected by 15 vulnerabilities spanning tenant isolation, privilege escalation, arbitrary code execution, authentication bypass, secret exposure, and denial of service. CVE-2026-70398 has a CVSS score of 9.6, Critical severity; CVE-2026-71471 has a CVSS score of 9.0, Critical severity; and CVE-2026-72508 and CVE-2026-72526 each have a CVSS score of 9.9, Critical severity. These flaws can expose spoke-cluster tokens, deploy arbitrary images or cluster-scoped resources, and compromise managed clusters.

CVE-2026-71473 has a CVSS score of 8.5, High severity; CVE-2026-66878 and CVE-2026-73122 are 7.7, High severity; and CVE-2026-71467 and CVE-2026-71469 are 7.5, High severity. The remaining six vulnerabilities are Medium severity, with CVSS scores from 5.0 to 6.5, and include credential leakage, excessive privileges, cross-namespace secret manipulation, and federated-search authorization weaknesses.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-441
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.