What is CVE-2026-70398?
This flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management. It allows an authenticated 'tenant' user to manipulate the GitOpsCluster controller and redirect sensitive spoke cluster bearer tokens. Affected systems should be patched immediately.
Azərbaycanca: Bu zəiflik Red Hat Advanced Cluster Management-in multicloud-integrations komponentində aşkarlanıb. Autentifikasiya olunmuş 'tenant' istifadəçiyə GitOpsCluster controller-i manipulyasiya edərək, həssas spoke cluster bearer token-lərini ələ keçirməyə imkan verir. Təsirə məruz qalan sistemlərdə dərhal yamaq tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: Red Hat
FAQ2
In which product was CVE-2026-70398 found?
This flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management.
What can an authenticated 'tenant' user achieve by exploiting CVE-2026-70398?
An authenticated 'tenant' user can manipulate the GitOpsCluster controller to redirect sensitive spoke cluster bearer tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.