PT-2026-36097 · Red Hat · Multicluster Engine+1

Nick Carboni

·

Published

2026-04-30

·

Updated

2026-05-19

·

CVE-2026-7163

CVSS v3.1

6.1

Medium

VectorAV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Multicluster Engine (affected versions not specified) Red Hat Advanced Cluster Management (affected versions not specified)
Description A flaw in the assisted-service REST API, an optional Assisted Installer component in the Multicluster Engine, enables an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for any cluster provisioned through the hub. In on-premises deployments using local authentication mode, the authenticator grants full administrative access to any request with a valid JSON Web Token (JWT) without per-endpoint restrictions. A valid local JWT is stored as a plaintext query parameter in InfraEnvStatus.ISODownloadURL, which is accessible to any user with read permissions for an InfraEnv object in their namespace. This allows attackers to access the credentials download endpoint "GET /v2/clusters/{cluster id}/credentials" to retrieve the kubeadmin password and the kubeconfig download endpoint, resulting in unrestricted root-level administrative access to spoke clusters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7163

Affected Products

Multicluster Engine
Red Hat Advanced Cluster Management