Red HatCVE-2026-73269
Red Hat cluster-curator-controller: privilege escalation
Critical9.9CVE-2026-73269 · Published Aug 12, 2026 · updated Sep 8, 2026
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
- www.cve.org/CVERecord?id=CVE-2026-73269
- nvd.nist.gov/vuln/detail/CVE-2026-73269
- access.redhat.com/errata/RHSA-2026:59556
- access.redhat.com/errata/RHSA-2026:59557
- access.redhat.com/errata/RHSA-2026:59558
- access.redhat.com/errata/RHSA-2026:59559
- access.redhat.com/errata/RHSA-2026:59579
- access.redhat.com/errata/RHSA-2026:59593
- access.redhat.com/security/cve/CVE-2026-73269
- bugzilla.redhat.com/show_bug.cgi?id=2514220
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Red Hat: mass assignment | High8.5 | No fix yet |
| Aug 12 | Red Hat insights-client. The: excessive privileges | Medium6.5 | No fix yet |
| Aug 12 | Red Hat search-v2-api: denial of service | High7.5 | No fix yet |
| Aug 12 | Red Hat acm-search-v2-rhel9: remote code execution | Critical9.0 | No fix yet |
| Aug 12 | Red Hat open-iscsi. This vulnerability: denial of service | Medium6.5 | No fix yet |
| Aug 12 | Red Hat open-iscsi: integer overflow | Medium6.5 | No fix yet |