Authorization Bypass in Multicluster Engine by Red Hat
CVE-2026-19130

5.8MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19130?

A vulnerability exists in the provider-credential-controller component of the Multicluster Engine, allowing attackers with specific permissions to exploit an authorization bypass. By manipulating the copiedFrom labels, they may intercept newly rotated provider credentials, which can result in unauthorized access to sensitive data. This poses substantial risks to the integrity and confidentiality of user information within the ecosystem.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.