CVE-2026-73268

Published Aug 12, 2026

Last updated 6 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-73268 is a code injection vulnerability found within the `cluster-curator-controller` component of the Multicluster Engine (MCE). The flaw allows a tenant possessing create or update permissions on `ClusterCurator` resources to inject an arbitrary Job specification. This occurs because the `CreateJob()` function fails to validate user-controlled input when unmarshaling the `spec.install.overrideJob` raw extension. Successful exploitation of this vulnerability enables the injected Job to execute with the elevated privileges of the controller. This can lead to arbitrary code execution, privilege escalation, and potential access to sensitive cluster-wide secrets.

Description
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.
Source
secalert@redhat.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secalert@redhat.com
CWE-94

Social media

Hype score
Not currently trending