boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-89060

multicluster-observability-addon — Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0047   38.9     —
AFFECTED
  Product                                                  Versions     Fixed
  multicluster-observability-addon                         unspecified  ad36a3ba9fd946c04de71621e47486f7aa2634fd
  Red Hat Advanced Cluster Management for Kubernetes 2.13  unspecified  1789126264
  Red Hat Advanced Cluster Management for Kubernetes 2.14  unspecified  1789126262
  Red Hat Advanced Cluster Management for Kubernetes 2.15  unspecified  1789126262
  Red Hat Advanced Cluster Management for Kubernetes 2.16  unspecified  1789126267
  Red Hat Advanced Cluster Management for Kubernetes 2.17  unspecified  1789126264
TIMELINE
  Sep 10  Reserved by redhat
  Sep 11  PATCH SHIPPED — CVE-2026-89060 (multicluster-observability-addon). Fixed in multicluster-observability-addon ad36a3ba9fd946c04de71621e47486f7aa2634fd.
  Sep 11  Published (CNA: redhat)
CWE-551 · CNA: redhat · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis

Description

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 10, 2026ReservedReserved by redhat
September 11, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-89060 (multicluster-observability-addon). Fixed in multicluster-observability-addon ad36a3ba9fd946c04de71621e47486f7aa2634fd.
September 11, 2026PublishedPublished (CNA: redhat)

Affected

Affected products and packages — 6 rows
VendorProduct / PackageEcosystemVersion introducedFixed
—multicluster-observability-addon——ad36a3ba9fd946c04de71621e47486f7aa2634fd
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.13——1789126264
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.14——1789126262
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.15——1789126262
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.16——1789126267
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.17——1789126264

Weaknesses

CWE-551

References (8)

Related

Authoritative record: CVE-2026-89060 at cve.org

Vendors: red hat

Weaknesses: CWE-551

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-89060 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.