CVE-2026-70398 is a confused-deputy vulnerability in the multicloud-integrations component of Red Hat Advanced Cluster Management for Kubernetes 2. An authenticated tenant can manipulate the GitOpsCluster controller, specifically by altering the GitOpsCluster configuration so that spoke-cluster bearer tokens are written to a namespace under the tenant's control rather than remaining in their intended secure location. The flaw arises from the controller performing privileged actions on behalf of a lower-privileged tenant without adequately constraining where sensitive credentials are deposited. As a result, bearer tokens associated with managed spoke clusters can be exposed to unauthorized tenants, enabling access beyond the tenant's intended authorization boundaries and undermining ArgoCD AppProject policy isolation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical confused-deputy vulnerability in Red Hat Advanced Cluster Management for Kubernetes (RHACM) multicloud-integrations that allows an authenticated tenant to redirect sensitive spoke-cluster bearer tokens to an attacker-controlled namespace, potentially enabling unauthorized access to spoke-cluster resources and policy bypass.
An access control/security policy bypass flaw in multicloud-integrations within Red Hat Advanced Cluster Management for Kubernetes 2 that allows an authenticated tenant to manipulate the GitOpsCluster controller and redirect sensitive spoke cluster bearer tokens to a namespace they control, enabling information disclosure and bypass of ArgoCD AppProject security policies.
Critical state manipulation / credential leakage vulnerability in Red Hat components involving the GitOpsCluster controller, allowing sensitive authentication tokens to be redirected to attacker-controlled namespaces or environments and potentially bypassing ArgoCD AppProject security policies.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.