Sceawere

Vulnerability Detail

CVE-2026-19130UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Provider-Credential-Controller Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.8
Creation Date
2h ago
Vendor
Red Hat
Product
Multicluster Engine for Kubernetes
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.8",
  "pubDate": "2026-08-12T21:17:37.703Z",
  "pubdate": "2026-08-12T21:17:37.703Z",
  "executiveSummary": "An authorization bypass vulnerability exists within the provider-credential-controller component of the multicluster-engine (MCE) product. This security flaw allows an authenticated actor with specific permissions on the hub cluster and prior knowledge of a credential value to exploit improper authorization controls.\nBy successfully manipulating designated labels within the system, specifically the copiedFrom labels, an attacker can intercept newly rotated provider credentials. This unauthorized interception leads directly to information disclosure, exposing sensitive provider credentials that are intended to be protected by standard security boundaries.\nThe risk implications include unauthorized access to critical infrastructure credentials managed across multicluster environments. Successful exploitation requires specific pre-existing privileges on the hub cluster and prior knowledge of an existing credential value, limiting the attack surface to actors who have already attained a baseline level of access within the target environment.",
  "technicalDetails": "The vulnerability resides in the authorization logic of the provider-credential-controller component within the multicluster-engine (MCE). The root cause stems from insufficient validation and authorization checks when processing resource metadata, specifically regarding the handling and interpretation of copiedFrom labels associated with provider credentials.\nThe vulnerable component is responsible for managing and rotating provider credentials across managed clusters. During the credential rotation lifecycle, the controller processes metadata inputs to track the lineage and source of copied credentials. Due to inadequate enforcement of access controls on these metadata fields, an attacker with specific permissions on the hub cluster can inject or manipulate copiedFrom labels.\nThe attack flow proceeds as follows: First, the attacker identifies or obtains prior knowledge of a valid credential value. Second, leveraging their specific permissions on the hub cluster, the attacker manipulates the copiedFrom labels on targeted resource objects. Third, when the provider-credential-controller processes the newly rotated credentials, the manipulated labels misdirect the controller's association logic.\nThis manipulation causes the controller to route or expose the newly rotated provider credentials to an unauthorized context or recipient controlled or accessed by the attacker. Consequently, the attacker achieves unauthorized information disclosure, gaining access to sensitive secret data that should be strictly protected by the authorization boundaries of the multicluster-engine architecture."
}
CVE-2026-19130: Provider-Credential-Controller Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 5.8) - Sceawere