Red HatCVE-2026-73266
A flaw was found in the clusterclaims-controller component of Multicluster...
High7.1CVE-2026-73266 · Published Aug 13, 2026 · updated Sep 8, 2026
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-441
- www.cve.org/CVERecord?id=CVE-2026-73266
- nvd.nist.gov/vuln/detail/CVE-2026-73266
- access.redhat.com/errata/RHSA-2026:59556
- access.redhat.com/errata/RHSA-2026:59557
- access.redhat.com/errata/RHSA-2026:59558
- access.redhat.com/errata/RHSA-2026:59559
- access.redhat.com/errata/RHSA-2026:59579
- access.redhat.com/errata/RHSA-2026:59593
- access.redhat.com/security/cve/CVE-2026-73266
- bugzilla.redhat.com/show_bug.cgi?id=2514217
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 13 | Red Hat Ansible Automation Platform 2: incomplete cleanup | Medium4.2 | No fix yet |
| Aug 13 | Red Hat sblim-sfcb: unsafe deserialization | Medium6.6 | No fix yet |
| Aug 13 | Red Hat sblim-sfcb. A local: race condition | Medium6.3 | No fix yet |
| Aug 13 | A flaw was found in sblim-cmpi-base | Medium6.3 | No fix yet |
| Aug 13 | Red Hat open-iscsi. An integer underflow vulnerability: integer overflow | Medium6.5 | No fix yet |
| Aug 12 | Red Hat: mass assignment | High8.5 | No fix yet |