All CVEs
Vulnerability intelligence

CVE-2026-73269

Red Hat multicluster engine for Kubernetes 2.10 CWE-269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.

CVSS Score
9.9
Critical
EPSS — Exploit Probability
0.6%
Riskier than 45% of all CVEs · checked 2026-10-01
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered Aug 17, 2026 · latest Aug 17, 2026

Coverage timeline

Related CVEs — Red Hat