PT-2026-36097 · Red Hat · Multicluster Engine+1
Nick Carboni
·
Published
2026-04-30
·
Updated
2026-05-19
·
CVE-2026-7163
CVSS v3.1
6.1
Medium
| Vector | AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Multicluster Engine (affected versions not specified)
Red Hat Advanced Cluster Management (affected versions not specified)
Description
A flaw in the assisted-service REST API, an optional Assisted Installer component in the Multicluster Engine, enables an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for any cluster provisioned through the hub. In on-premises deployments using local authentication mode, the authenticator grants full administrative access to any request with a valid JSON Web Token (JWT) without per-endpoint restrictions. A valid local JWT is stored as a plaintext query parameter in
InfraEnvStatus.ISODownloadURL, which is accessible to any user with read permissions for an InfraEnv object in their namespace. This allows attackers to access the credentials download endpoint "GET /v2/clusters/{cluster id}/credentials" to retrieve the kubeadmin password and the kubeconfig download endpoint, resulting in unrestricted root-level administrative access to spoke clusters.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multicluster Engine
Red Hat Advanced Cluster Management