Authorization Bypass in Multicluster Engine by Red Hat
CVE-2026-19130
5.8MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 12 August 2026
What is CVE-2026-19130?
A vulnerability exists in the provider-credential-controller component of the Multicluster Engine, allowing attackers with specific permissions to exploit an authorization bypass. By manipulating the copiedFrom labels, they may intercept newly rotated provider credentials, which can result in unauthorized access to sensitive data. This poses substantial risks to the integrity and confidentiality of user information within the ecosystem.
Affected Version(s)
multicluster engine for Kubernetes 2.10 1787176886
multicluster engine for Kubernetes 2.11 1787239595
multicluster engine for Kubernetes 2.17 1786664288