A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat multicluster Engine For Kubernetes
|
|
| Vendors & Products |
Redhat multicluster Engine For Kubernetes
|
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools. | |
| Title | Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T20:55:28.504Z
Reserved: 2026-08-11T17:22:38.645Z
Link: CVE-2026-73269
Updated: 2026-08-12T20:47:07.044Z
Status : Received
Published: 2026-08-12T20:17:53.793
Modified: 2026-08-12T21:17:40.420
Link: CVE-2026-73269
No data.
OpenCVE Enrichment
Updated: 2026-08-13T00:00:09Z