Unauthorized Access Vulnerability in Multicluster Engine by Red Hat
CVE-2026-73266
7.1HIGH
What is CVE-2026-73266?
A flaw in the clusterclaims-controller of the Multicluster Engine allows authenticated tenants to manipulate ClusterClaim labels. This vulnerability can potentially let a tenant force a cluster to join a ManagedClusterSet belonging to another tenant. This unauthorized access opens the door for the injection of policies and workloads into clusters, which can disrupt operations and compromise security across environments.