Database/Container, Kubernetes & orchestration
Multicluster Engine cluster-proxy-addon: unauthenticated path manipulation proxies to any managed-cluster service
Impact
The cluster-proxy-addon exposes a user-facing route that is supposed to authenticate and authorize before proxying into managed clusters. By manipulating URL path segments an unauthenticated caller skips those checks and has the addon proxy requests to arbitrary services in any cluster the hub manages. Where Multicluster Engine or ACM is the hub for a GPU fleet, that route is a single unauthenticated door into internal services on every managed cluster — operator endpoints, metrics, and other in-cluster APIs that were never meant to face the network. The CVSS vector is scope-changed, reflecting that the compromise crosses from the hub into the managed clusters.
Who can reach it
Anyone who can reach the cluster-proxy-addon user-facing route. No authentication required; if that route is published on a public ingress, this is internet-reachable.
What to do
Track the Red Hat advisory for the fixed Multicluster Engine release — the record does not name a fixed version. In the meantime, remove public exposure of the cluster-proxy route and restrict it to the management network or a VPN. Applying the update rolls the addon pods on the hub; managed-cluster workloads and GPU nodes are not disturbed.
References
Related entries
- Traefik: crafted Host port bypasses BasicAuth and IP allowlists on ingress-nginx annotated IngressesCVE-2026-88877 · Traefik ingress-nginx provider (from-to-www-redirect sibling router)Critical
- Kata Containers: runtime-rs standalone virtio-fs path is vulnerable to a guest-to-host escapeCVE-2026-47243 · Kata ContainersCritical
- Cilium: With L7 enabled, the embedded Envoy exposes a world-accessible admin.sock on the clusterCVE-2026-49445 · CiliumCritical
- Rancher: Anyone who can create role template bindings escalates privileges cluster-wideCVE-2022-31247 · RancherCritical
- Argo CD: Improper authorization lets a user modify resources outside their permitted projectsCVE-2023-23947 · Argo CDCritical
- OpenShift GitOps: namespace admin can escalate via ArgoCD CRs to root on control-plane nodesCVE-2025-13888 · Red Hat OpenShift GitOps (Argo CD operator, ArgoCD custom resource handling)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.