CVE-2026-91182

Description

A flaw was found in open-cluster-management. An agent communicating via the gRPC broker can bypass authorization by manipulating the ce-clustername cloud event header attribute, which is used for authorization, independently of the actual event payload. This allows a registered managed cluster to gain unauthorized access, enabling it to move itself into other tenants' ManagedClusterSets and overwrite other clusters' ManagedCluster objects in the hub. The primary consequence is a breach of isolation between managed clusters, leading to unauthorized modification of cluster resources. This can lead to unauthorized receipt of newly delivered tenant workloads, policies, and secrets via Placement decisions. Additionally, an attacker can arbitrarily overwrite other clusters' ManagedCluster objects on the hub or perform unauthorized writes inside another cluster's dedicated hub namespace, such as forging Lease liveness heartbeats to manipulate availability status.

Statement

Red Hat Product Security has scored this vulnerability as Low as this feature is disabled by default in Red Hat out of the box configurations. This is also not the default path in upstream Open Cluster Management. In addition, if an attacker is able to move a cluster to a different ManageCluster object, all they can do is run a predetermined payload on the wrong cluster. There is no risk to existing payloads in terms of integrity or confidentiality.

The gRPC registration driver is disabled by default and represents an incomplete, work-in-progress feature path that currently lacks support for core capabilities such as OCM Addons.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Access control checks for specific user data or functionality can be bypassed.

Access Control

Technical Impact: Gain Privileges or Assume Identity

Horizontal escalation of privilege is possible (one user can view/modify information of another user).

Access Control

Technical Impact: Gain Privileges or Assume Identity

Vertical escalation of privilege is possible if the user-controlled key is actually a flag that indicates administrator status, allowing the attacker to gain administrative access.

Acknowledgements

Red Hat would like to thank Elias Hasas (Brickell Technologies, LLC.) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.