Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-73269: OpenShift: Cluster-wide secrets access via tenant-controllable trigger
CVE-2026-73269 · published 22 days ago
Summary
An attacker in a specific namespace can create a resource that grants them access to sensitive cluster-wide secrets and elevated permissions. This is a significant risk because it allows the attacker to access and manipulate critical system data. To mitigate this, update the cluster-curator-controller component to prevent this type of privilege escalation.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | multicluster engine for kubernetes | All versions |
| red hat | multicluster engine for kubernetes 2.11 | All versions |
| red hat | multicluster engine for kubernetes 2.17 | All versions |
Original advisory text
Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.
References
- https://access.redhat.com/security/cve/CVE-2026-73269 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2514220 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59556 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59593
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published12 Aug 2026
Updated30 Aug 2026
First seen12 Aug 2026
Monitor software like this
Free during beta