Privilege Escalation Vulnerability in Cluster Curator Component by Red Hat
CVE-2026-73269
9.9CRITICAL
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 12 August 2026
What is CVE-2026-73269?
A vulnerability exists within the cluster-curator-controller component that enables a local user to escalate privileges. By creating a ClusterCurator resource with a specific naming convention, the attacker can trigger the generation of a cluster-scoped ClusterRoleBinding. This process grants the user excessive privileges, which include not only access to manipulate sensitive secrets but also control over cluster management tasks, potentially allowing them to delete entire hosted clusters or node pools.
Affected Version(s)
multicluster engine for Kubernetes 2.10 1787201612
multicluster engine for Kubernetes 2.11 1787238383
multicluster engine for Kubernetes 2.17 1786750700