CVE-2026-73269 – Red Hat Multicluster Engine for Kubernetes

CVSS 9.9 CRITICAL Critical - Same Day Deployment

“Tenant-level access can cross critical cluster boundaries and escalate into code execution or cluster-wide control.”

Red Hat Multicluster Engine for Kubernetes is affected by four vulnerabilities involving privilege boundaries, tenant isolation, and credential protection. CVE-2026-73268 has a CVSS score of 9.9, Critical severity and can allow injected jobs to execute arbitrary code with elevated controller privileges. CVE-2026-73269 has a CVSS score of 9.9, Critical severity and can escalate namespace-level access to cluster-wide control.

CVE-2026-73266 has a CVSS score of 7.1, High severity and can allow a tenant to improperly associate clusters with another tenant’s ManagedClusterSet. CVE-2026-19130 has a CVSS score of 5.8, Medium severity and can expose newly rotated provider credentials through an authorization bypass.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-269
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.