Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-73268: Multicluster Engine: Privilege Escalation via Job Injection

CVE-2026-73268 · published 22 days ago
Summary

An attacker with specific permissions can inject malicious code into a critical system component, potentially gaining elevated privileges and accessing sensitive information. This vulnerability affects the Multicluster Engine, and it's essential to update the system to a patched version to prevent exploitation. IT teams should prioritize applying the latest security patches to minimize the risk of attack.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat multicluster engine for kubernetes All versions
red hat multicluster engine for kubernetes 2.11 All versions
red hat multicluster engine for kubernetes 2.17 All versions
Original advisory text
Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Sources
CVE-2026-73268 · MITRE
Monitor software like this
Free during beta