Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-73269: OpenShift: Cluster-wide secrets access via tenant-controllable trigger

CVE-2026-73269 · published 22 days ago
Summary

An attacker in a specific namespace can create a resource that grants them access to sensitive cluster-wide secrets and elevated permissions. This is a significant risk because it allows the attacker to access and manipulate critical system data. To mitigate this, update the cluster-curator-controller component to prevent this type of privilege escalation.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat multicluster engine for kubernetes All versions
red hat multicluster engine for kubernetes 2.11 All versions
red hat multicluster engine for kubernetes 2.17 All versions
Original advisory text
Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Sources
CVE-2026-73269 · MITRE
Monitor software like this
Free during beta