Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-73268: Multicluster Engine: Privilege Escalation via Job Injection
CVE-2026-73268 · published 22 days ago
Summary
An attacker with specific permissions can inject malicious code into a critical system component, potentially gaining elevated privileges and accessing sensitive information. This vulnerability affects the Multicluster Engine, and it's essential to update the system to a patched version to prevent exploitation. IT teams should prioritize applying the latest security patches to minimize the risk of attack.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | multicluster engine for kubernetes | All versions |
| red hat | multicluster engine for kubernetes 2.11 | All versions |
| red hat | multicluster engine for kubernetes 2.17 | All versions |
Original advisory text
Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.
References
- https://access.redhat.com/security/cve/CVE-2026-73268 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2514219 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59556 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59593
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta