CRITICAL 9.9 NVD

CVE-2026-72526

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Applica

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.

References

Published: 2026-08-12 · Source: NVD · Feed updated: 2026-08-12
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-08-12 via NVD.

Risk Timeline

CVE Disclosed2026-08-12 · -1 days ago

Remediation Resources

vulnfeed aggregates 9985 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.