AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72526

CRITICAL · CVSS 9.9 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the multicloud-integrations component, where the Application propagation controller improperly validates the `ocm-managed-cluster` annotation from Application Custom Resources. This flaw allows an authenticated tenant to exploit the system, potentially synchronizing malicious manifests in managed clusters, which could result in arbitrary code execution or privilege escalation. Organizations using this component, particularly those with multi-tenant environments, should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72526
Severity
CRITICAL
CVSS
9.9
EPSS
0.30%

Original NVD Description

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.