SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89060

HIGH · CVSS 7.7 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in the multicluster-observability-addon allows a managed-cluster identity to access configuration resources beyond its designated namespace, potentially exposing sensitive hub Secrets to unauthorized access. Organizations utilizing this addon should prioritize remediation efforts due to the high severity of the issue, which could lead to significant data breaches. Immediate action is recommended for those managing multi-cluster environments to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-89060
Severity
HIGH
CVSS
7.7
EPSS
0.23%

Original NVD Description

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.