CVE-2026-72526 is a critical authorization-bypass vulnerability in the multicloud-integrations component of Red Hat Advanced Cluster Management for Kubernetes 2. The flaw is in the Application propagation controller, which processes the ocm-managed-cluster annotation from an Application Custom Resource without proper validation. A tenant with permission to create Application resources on the hub cluster can abuse this behavior to direct propagation toward arbitrary managed spoke clusters outside the intended authorization boundary. By causing ArgoCD on targeted spoke clusters to synchronize attacker-controlled manifests, the vulnerability can be leveraged to execute arbitrary code or escalate privileges on those clusters, including compromise at highly privileged cluster scope.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
ocm-managed-cluster annotation before returning affected environments to normal multi-tenant operation.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in the multicloud-integrations component of Red Hat Advanced Cluster Management for Kubernetes 2 where improper validation of the `ocm-managed-cluster` annotation in an Application Custom Resource allows a tenant with application creation permissions on the hub cluster to target arbitrary managed clusters, potentially causing ArgoCD on spoke clusters to sync attacker-controlled manifests and resulting in arbitrary code execution or privilege escalation.
A critical authorization/validation flaw in Red Hat Advanced Cluster Management's multicloud-integrations component that lets a tenant with Application creation permissions on the hub cluster target arbitrary managed spoke clusters, potentially causing attacker-controlled manifest synchronization and resulting in arbitrary code execution or privilege escalation, including cluster-admin access on spoke clusters.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.