CVE-2026-73266
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-441
- Published
- 2026-08-13
- Last modified
- 2026-09-08
Affected products
- Red Hat multicluster engine for Kubernetes 2.9.0
- Red Hat multicluster engine for Kubernetes 2.11
- Red Hat multicluster engine for Kubernetes 2.17
- Red Hat multicluster engine for Kubernetes 2.10
- Red Hat multicluster engine for Kubernetes 2.6
- Red Hat multicluster engine for Kubernetes 2.8
- Red Hat multicluster engine for Kubernetes 2.9
- Red Hat multicluster engine for Kubernetes 2.1
Weakness type
Related vulnerabilities
- CVE-2026-87502 — Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-87582 — Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87442 — Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who...
- CVE-2026-87453 — Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-69531 — Microsoft Windows Speech Tampering Vulnerability
- CVE-2026-86600 — Workload identity attestation generated before login host validation in Snowflake drivers
- CVE-2026-86115 — Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ Path
- CVE-2026-84329 — Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed...