Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, restrict the ability of tenants to create `ClusterCurator` resources. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit `create` permissions for `clustercurators.cluster.open-cluster-management.io` resources to only trusted administrators or service accounts. Alternatively, deploy an admission controller to enforce that `metadata.name` and `metadata.namespace` fields are identical when `ClusterCurator` resources are created, preventing the vulnerable condition.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat multicluster Engine For Kubernetes
|
|
| Vendors & Products |
Redhat multicluster Engine For Kubernetes
|
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools. | |
| Title | Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T20:55:28.504Z
Reserved: 2026-08-11T17:22:38.645Z
Link: CVE-2026-73269
Updated: 2026-08-12T20:47:07.044Z
Status : Received
Published: 2026-08-12T20:17:53.793
Modified: 2026-08-12T21:17:40.420
Link: CVE-2026-73269
No data.
OpenCVE Enrichment
Updated: 2026-08-12T21:30:07Z