All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-72526
CRITICALpublished 2026-08-12 02:16 UTC · 1 day ago · modified 2026-08-12 13:17 UTC
9.9
CVSS / 10
// description
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary managed clusters. This can force ArgoCD on the spoke clusters to synchronize attacker-controlled manifests, leading to arbitrary code execution or privilege escalation on those clusters.
// weaknesses (CWE)
- CWE-441