Red HatCVE-2026-19130
provider-credential-controller: information disclosure
Medium5.8CVE-2026-19130 · Published Aug 12, 2026 · updated Sep 8, 2026
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
- www.cve.org/CVERecord?id=CVE-2026-19130
- nvd.nist.gov/vuln/detail/CVE-2026-19130
- access.redhat.com/errata/RHSA-2026:59556
- access.redhat.com/errata/RHSA-2026:59557
- access.redhat.com/errata/RHSA-2026:59558
- access.redhat.com/errata/RHSA-2026:59559
- access.redhat.com/errata/RHSA-2026:59579
- access.redhat.com/errata/RHSA-2026:59593
- access.redhat.com/security/cve/CVE-2026-19130
- bugzilla.redhat.com/show_bug.cgi?id=2512105
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Red Hat: mass assignment | High8.5 | No fix yet |
| Aug 12 | Red Hat insights-client. The: excessive privileges | Medium6.5 | No fix yet |
| Aug 12 | Red Hat search-v2-api: denial of service | High7.5 | No fix yet |
| Aug 12 | Red Hat acm-search-v2-rhel9: remote code execution | Critical9.0 | No fix yet |
| Aug 12 | Red Hat open-iscsi. This vulnerability: denial of service | Medium6.5 | No fix yet |
| Aug 12 | Red Hat open-iscsi: integer overflow | Medium6.5 | No fix yet |