Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-89060
multicluster-observability-addon — Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C H N N 7.7 .0047 38.9 —
AFFECTED
Product Versions Fixed
multicluster-observability-addon unspecified ad36a3ba9fd946c04de71621e47486f7aa2634fd
Red Hat Advanced Cluster Management for Kubernetes 2.13 unspecified 1789126264
Red Hat Advanced Cluster Management for Kubernetes 2.14 unspecified 1789126262
Red Hat Advanced Cluster Management for Kubernetes 2.15 unspecified 1789126262
Red Hat Advanced Cluster Management for Kubernetes 2.16 unspecified 1789126267
Red Hat Advanced Cluster Management for Kubernetes 2.17 unspecified 1789126264
TIMELINE
Sep 10 Reserved by redhat
Sep 11 PATCH SHIPPED — CVE-2026-89060 (multicluster-observability-addon). Fixed in multicluster-observability-addon ad36a3ba9fd946c04de71621e47486f7aa2634fd.
Sep 11 Published (CNA: redhat)
Description
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 10, 2026 | Reserved | Reserved by redhat |
| September 11, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-89060 (multicluster-observability-addon). Fixed in multicluster-observability-addon ad36a3ba9fd946c04de71621e47486f7aa2634fd. |
| September 11, 2026 | Published | Published (CNA: redhat) |
Affected
Affected products and packages — 6 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| — | multicluster-observability-addon | — | — | ad36a3ba9fd946c04de71621e47486f7aa2634fd |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.13 | — | — | 1789126264 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.14 | — | — | 1789126262 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.15 | — | — | 1789126262 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.16 | — | — | 1789126267 |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.17 | — | — | 1789126264 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-89060 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.