What is CVE-2026-72526?
CVE-2026-72526 is a flaw in the multicloud-integrations component where the Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this vulnerability. Updating the affected component is recommended to mitigate the risk.
Azərbaycanca: CVE-2026-72526 `multicloud-integrations` komponentində tapılmış boşluqdur: Application propagation controller, Application CR-dən `ocm-managed-cluster` annotasiyasını lazımi yoxlama olmadan emal edir. Hub cluster-də Application yaratmaq icazəsi olan tenant bu boşluqdan istifadə edə bilər. Təsirə məruz qalmamaq üçün bu komponentin yenilənməsi tövsiyə olunur.
FAQ2
In which component was the CVE-2026-72526 vulnerability discovered?
The CVE-2026-72526 vulnerability was discovered in the `multicloud-integrations` component.
How can a threat actor exploit this vulnerability?
A tenant with permissions to create Applications on the hub cluster can exploit this flaw because the Application propagation controller processes the `ocm-managed-cluster` annotation without proper validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.