Sceawere

Vulnerability Detail

CVE-2026-73266UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Multicluster Engine ClusterClaim Label Manipulation

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
Red Hat
Product
Multicluster Engine for Kubernetes
Attack Type
Unintended Proxy or Intermediary ('Confused Deputy')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-13T17:17:35.713Z",
  "pubdate": "2026-08-13T17:17:35.713Z",
  "executiveSummary": "A privilege escalation and cross-tenant access vulnerability exists within the clusterclaims-controller component of Multicluster Engine (MCE). This security flaw enables an authenticated tenant to manipulate ClusterClaim labels, bypassing standard multi-tenancy isolation boundaries. By successfully exploiting this vulnerability, an unauthorized tenant can force a target cluster to erroneously join a ManagedClusterSet belonging to a completely separate tenant. The business impact of this compromise is severe, as unauthorized cross-tenant cluster association directly enables malicious actors to inject unauthorized policies, configurations, and arbitrary workloads into foreign tenants' clusters. Exploitation requires authenticated access within the environment and the capability to manipulate specific object labels associated with the clusterclaims-controller. The risk implication is a total breach of tenant isolation within the multicluster orchestration environment, potentially cascading into widespread unauthorized control over managed infrastructure.",
  "technicalDetails": "The vulnerability resides within the clusterclaims-controller component of Multicluster Engine (MCE), specifically in how it processes and validates object labels on ClusterClaim resources. The root cause stems from insufficient validation and authorization checks when mapping cluster claims to ManagedClusterSets based on user-supplied label inputs. An authenticated tenant possessing permissions to interact with or modify their own ClusterClaim resources can leverage improper label sanitization to trigger unintended association logic within the controller.\nThe attack flow proceeds as follows: First, the authenticated attacker crafts or modifies a ClusterClaim resource within their accessible namespace, injecting specific manipulated labels designed to target a foreign ManagedClusterSet. Second, the clusterclaims-controller processes the modified ClusterClaim without adequately verifying whether the issuing tenant holds explicit authorization to bind resources to the specified destination ManagedClusterSet. Third, the controller evaluates the manipulated labels and forces the target cluster to join the unauthorized ManagedClusterSet.\nPost-exploitation impact includes severe integrity and confidentiality violations across the orchestration plane. Because membership in a ManagedClusterSet typically grants administrative boundaries, permissions, and automated policy propagation, successful redirection allows the malicious tenant to inject arbitrary governance policies and deploy unauthorized workloads into the victim tenant's managed clusters. Authentication and privilege requirements are constrained to an authenticated tenant who has access to manipulate ClusterClaim resources. The vulnerability exposes weaknesses in tenant boundary enforcement within the clusterclaims-controller component."
}
CVE-2026-73266: Multicluster Engine ClusterClaim Label Manipulation (HIGH Severity, CVSS: 7.1) - Sceawere