{
  "threat_severity" : "Critical",
  "public_date" : "2026-08-10T13:40:00Z",
  "bugzilla" : {
    "description" : "multicluster-global-hub: Cross-hub lateral movement via shared spec-topic Write ACL and spoofable CloudEvent identity",
    "id" : "2508045",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2508045"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-290",
  "details" : [ "A flaw was found in multicluster-global-hub. An attacker who compromises a managed hub can leverage its legitimate Kafka client certificate to publish a CloudEvent (a specification for describing event data in a common way) message to the shared `gh-spec` topic. This message can spoof its source as \"global-hub\" and target other managed hubs. Due to a lack of binding between the Kafka client principal and the CloudEvent envelope, the agent on the targeted hub accepts this spoofed message and applies arbitrary resources. This vulnerability allows for fleet-wide cluster-admin privilege escalation across all managed hubs." ],
  "statement" : "Critical: The default Strimzi transport in Multicluster Global Hub is vulnerable to privilege escalation. A compromised managed hub can exploit weak Kafka Write ACLs on the shared `gh-spec` topic and spoofed CloudEvent sources to gain cluster-admin privileges across the entire fleet of managed hubs. This allows an attacker to achieve fleet-wide administrative control from a single compromised leaf hub.",
  "affected_release" : [ {
    "product_name" : "Multicluster Global Hub 1.4.5",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55810",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.4::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416",
    "impact" : "critical"
  }, {
    "product_name" : "Multicluster Global Hub 1.6.5",
    "release_date" : "2026-08-12T00:00:00Z",
    "advisory" : "RHSA-2026:54392",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.6::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343",
    "impact" : "critical"
  }, {
    "product_name" : "Multicluster Global Hub 1.7.0",
    "release_date" : "2026-08-11T00:00:00Z",
    "advisory" : "RHSA-2026:53530",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214",
    "impact" : "critical"
  }, {
    "product_name" : "Multicluster Global Hub 1.8.0",
    "release_date" : "2026-08-10T00:00:00Z",
    "advisory" : "RHSA-2026:52946",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.8::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967",
    "impact" : "critical"
  }, {
    "product_name" : "Red Hat multicluster global hub 1.5.1",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54577",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.5::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621343",
    "impact" : "critical"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-66801\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-66801" ],
  "name" : "CVE-2026-66801",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}