Sceawere
Vulnerability Detail
CVE-2026-19130UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Provider-Credential-Controller Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.8
- Creation Date
- 2h ago
- Vendor
- Red Hat
- Product
- Multicluster Engine for Kubernetes
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.8",
"pubDate": "2026-08-12T21:17:37.703Z",
"pubdate": "2026-08-12T21:17:37.703Z",
"executiveSummary": "An authorization bypass vulnerability exists within the provider-credential-controller component of the multicluster-engine (MCE) product. This security flaw allows an authenticated actor with specific permissions on the hub cluster and prior knowledge of a credential value to exploit improper authorization controls.\nBy successfully manipulating designated labels within the system, specifically the copiedFrom labels, an attacker can intercept newly rotated provider credentials. This unauthorized interception leads directly to information disclosure, exposing sensitive provider credentials that are intended to be protected by standard security boundaries.\nThe risk implications include unauthorized access to critical infrastructure credentials managed across multicluster environments. Successful exploitation requires specific pre-existing privileges on the hub cluster and prior knowledge of an existing credential value, limiting the attack surface to actors who have already attained a baseline level of access within the target environment.",
"technicalDetails": "The vulnerability resides in the authorization logic of the provider-credential-controller component within the multicluster-engine (MCE). The root cause stems from insufficient validation and authorization checks when processing resource metadata, specifically regarding the handling and interpretation of copiedFrom labels associated with provider credentials.\nThe vulnerable component is responsible for managing and rotating provider credentials across managed clusters. During the credential rotation lifecycle, the controller processes metadata inputs to track the lineage and source of copied credentials. Due to inadequate enforcement of access controls on these metadata fields, an attacker with specific permissions on the hub cluster can inject or manipulate copiedFrom labels.\nThe attack flow proceeds as follows: First, the attacker identifies or obtains prior knowledge of a valid credential value. Second, leveraging their specific permissions on the hub cluster, the attacker manipulates the copiedFrom labels on targeted resource objects. Third, when the provider-credential-controller processes the newly rotated credentials, the manipulated labels misdirect the controller's association logic.\nThis manipulation causes the controller to route or expose the newly rotated provider credentials to an unauthorized context or recipient controlled or accessed by the attacker. Consequently, the attacker achieves unauthorized information disclosure, gaining access to sensitive secret data that should be strictly protected by the authorization boundaries of the multicluster-engine architecture."
}