Authorization Bypass in Multicluster Engine by Red Hat
CVE-2026-19130
5.8MEDIUM
What is CVE-2026-19130?
A vulnerability exists in the provider-credential-controller component of the Multicluster Engine, allowing attackers with specific permissions to exploit an authorization bypass. By manipulating the copiedFrom labels, they may intercept newly rotated provider credentials, which can result in unauthorized access to sensitive data. This poses substantial risks to the integrity and confidentiality of user information within the ecosystem.