CVE-2026-73269 – Red Hat Multicluster Engine for Kubernetes
“Tenant-level access can cross critical cluster boundaries and escalate into code execution or cluster-wide control.”
Red Hat Multicluster Engine for Kubernetes is affected by four vulnerabilities involving privilege boundaries, tenant isolation, and credential protection. CVE-2026-73268 has a CVSS score of 9.9, Critical severity and can allow injected jobs to execute arbitrary code with elevated controller privileges. CVE-2026-73269 has a CVSS score of 9.9, Critical severity and can escalate namespace-level access to cluster-wide control.
CVE-2026-73266 has a CVSS score of 7.1, High severity and can allow a tenant to improperly associate clusters with another tenant’s ManagedClusterSet. CVE-2026-19130 has a CVSS score of 5.8, Medium severity and can expose newly rotated provider credentials through an authorization bypass.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-269