Privilege Escalation Vulnerability in Cluster Curator Component by Red Hat
CVE-2026-73269

9.9CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73269?

A vulnerability exists within the cluster-curator-controller component that enables a local user to escalate privileges. By creating a ClusterCurator resource with a specific naming convention, the attacker can trigger the generation of a cluster-scoped ClusterRoleBinding. This process grants the user excessive privileges, which include not only access to manipulate sensitive secrets but also control over cluster management tasks, potentially allowing them to delete entire hosted clusters or node pools.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.