Skip to content
Red HatCVE-2026-73266

A flaw was found in the clusterclaims-controller component of Multicluster...

High7.1CVE-2026-73266 · Published Aug 13, 2026 · updated Sep 8, 2026

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Ansible Automation Platform 2: incomplete cleanup
Medium4.2Aug 13
Red Hat sblim-sfcb: unsafe deserialization
Medium6.6Aug 13
Red Hat sblim-sfcb. A local: race condition
Medium6.3Aug 13
A flaw was found in sblim-cmpi-base
Medium6.3Aug 13
Red Hat open-iscsi. An integer underflow vulnerability: integer overflow
Medium6.5Aug 13
Red Hat: mass assignment
High8.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.