Red Hat Security Advisory: Multicluster Global Hub 1.4.8 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33376 — grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-42306 — github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-66801 — multicluster-global-hub: multicluster-global-hub: shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
🎯 Affected products22
- Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:2166fa9885345c3be7c43fa459b1606f61ac9f35cc53abb65dd8fd5e6b4b93de_arm64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:5437ebf7e21bedbab79890bdbeba005cc08558e2015ed69868f0297de88b0a36_s390x as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:8439f0dbf7a2504ecf9291a23341c80a65d6da91bcae6eeba57b613e8839033a_amd64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:f65ef27e2fc9146b99e248c57a9dbe4232201c4640733012f1116ff5686b6d2a_ppc64le as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:6c28ae3f509e4b42d61be90decb14af658bf114bcb6e429d862b7580fa577483_s390x as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:792974503a47cc45b138cf96c4dfc68a4e223053b4a2d66f04e346d1d302cd20_arm64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:7b10f2f08780249626214d5fa10f700972d2f27ab8d8c59cc48675f7b17f798f_amd64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:801d982bac8568fbe1a8655a334cffb812752b1e1677f5e6615137a5c1b60df3_ppc64le as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:6595a7acc86d1c40254cca9ca11cfee1c132c3c95151c4c0f850a76883628a3e_arm64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:74cb04ff8483d2c80705f7fda65481389256a51ba0f27809e772854060dc41a4_amd64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:aac78bba7d135fa6848e46238033c77f7353a24c5ea4cea59ae5f9b6663ef2d7_s390x as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:dc6852b0a21fc18cc69c3a05b4a59af12a29435972f82ffd68dc8b684ea96241_ppc64le as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:00387b28fb61aba5e23599be853aa3d1ca2ac60c61210ebab3b143b6240654b8_amd64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:13cf42dcaa7e81a55d0ec079e7c30dc94f170b5c2afc25563c9e76ba194b3e66_s390x as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:24425ecd3298355d2dacd8916076a53effc47d75c5ad4eaad3315e81676bc6ab_amd64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:44398c0c69a843b38209fa0f34264396e7985fd47a802329c04ccc98c1855130_arm64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:5f0bf5ac15dc9b542eebb9d0bba9e5f764a8ea772d6dd096f219458786fcaade_ppc64le as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:53ab458b15b639a3fa185a26995817d05c2379d9757b370a6cf078c9b5519fe8_ppc64le as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:7c20f24f0cd291831d8857c087fd5332ce0f72e365faece2db881517f594f9d5_amd64 as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:f29739944614d96575fb1a9e2df3a11fa7bf9fe861b555d6d9092d6eea8f2565_s390x as a component of Multicluster Global Hub 1.4.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:f9e15fced05d8b4301a11cbddb4e7a04b92db52badf4459771d0ce83ec195dea_arm64 as a component of Multicluster Global Hub 1.4.8
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index Workaround: To mitigate this issue, explicitly specify the intended IPv6 address mask—typically /128 for a single host—within the Grafana Auth Proxy allow-list configuration. This overrides the incorrect default /32 mask, ensuring that network access restrictions are applied strictly as intended. For RHEL: Update the whitelist directive under the [auth.proxy] section in /etc/grafana/grafana.ini. For example, if ::1 is the desired address, configure it explicitly as ::1/128. A restart of the Grafana service (systemctl restart grafana-server) is required for the changes to take effect. Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:55810
- externalhttps://access.redhat.com/security/cve/CVE-2026-33376
- externalhttps://access.redhat.com/security/cve/CVE-2026-33377
- externalhttps://access.redhat.com/security/cve/CVE-2026-42306
- externalhttps://access.redhat.com/security/cve/CVE-2026-55969
- externalhttps://access.redhat.com/security/cve/CVE-2026-66801
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55810.json