AI description
CVE-2026-73268 is a code injection vulnerability found within the `cluster-curator-controller` component of the Multicluster Engine (MCE). The flaw allows a tenant possessing create or update permissions on `ClusterCurator` resources to inject an arbitrary Job specification. This occurs because the `CreateJob()` function fails to validate user-controlled input when unmarshaling the `spec.install.overrideJob` raw extension. Successful exploitation of this vulnerability enables the injected Job to execute with the elevated privileges of the controller. This can lead to arbitrary code execution, privilege escalation, and potential access to sensitive cluster-wide secrets.
- Description
- A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.
- Source
- secalert@redhat.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- secalert@redhat.com
- CWE-94
- Hype score
- Not currently trending
🚨 CRITICAL: Red Hat has patched two CVSS 9.9 remote code execution flaws in Red Hat Advanced Cluster Management (RHACM). Tracked as CVE-2026-72526 and CVE-2026-73268, both vulnerabilities can potentially lead to remote code execution in affected environments. Admins should h
@ThreatWire_
17 Aug 2026
1532 Impressions
5 Retweets
15 Likes
4 Bookmarks
2 Replies
0 Quotes
Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps. #RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec https://t.co/Nd7b9tj2CG
@Daily_CyberSec
17 Aug 2026
409 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes