CVE-2026-73269
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.33%
- CWE
- CWE-269
- Published
- 2026-08-12
- Last modified
- 2026-09-08
Affected products
- Red Hat multicluster engine for Kubernetes 2.9.0
- Red Hat multicluster engine for Kubernetes 2.11
- Red Hat multicluster engine for Kubernetes 2.17
- Red Hat multicluster engine for Kubernetes 2.10
- Red Hat multicluster engine for Kubernetes 2.6
- Red Hat multicluster engine for Kubernetes 2.8
- Red Hat multicluster engine for Kubernetes 2.9
- Red Hat multicluster engine for Kubernetes 2.1
Weakness type
Related vulnerabilities
- CVE-2026-84869 — ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
- CVE-2026-79090 — Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci
- CVE-2026-79226 — Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
- CVE-2026-78999 — Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co
- CVE-2026-9193 — Privilege escalation in Progress MarkLogic Server Hadoop integration
- CVE-2026-8709 — Privilege escalation in Progress MarkLogic Server REST document patch operation
- CVE-2026-7329 — Privilege escalation in Progress MarkLogic Server REST query interfaces
- CVE-2026-72886 — Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632)