A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat multicluster Engine For Kubernetes
|
|
| Vendors & Products |
Redhat multicluster Engine For Kubernetes
|
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected. | |
| Title | Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T20:46:21.305Z
Reserved: 2026-08-06T15:55:10.000Z
Link: CVE-2026-19130
No data.
Status : Received
Published: 2026-08-12T21:17:37.703
Modified: 2026-08-12T21:17:37.703
Link: CVE-2026-19130
No data.
OpenCVE Enrichment
Updated: 2026-08-13T02:30:12Z