Sceawere

Vulnerability Detail

CVE-2026-73269UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cluster Curator Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
2h ago
Vendor
Red Hat
Product
Multicluster Engine for Kubernetes
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-08-12T20:17:53.793Z",
  "pubdate": "2026-08-12T20:17:53.793Z",
  "executiveSummary": "A privilege escalation vulnerability has been identified within the cluster-curator-controller component, exposing clusters to significant security risks through unauthorized cluster-scoped access.\nThe vulnerability allows a local user with restricted, namespace-local access to achieve full cluster-wide control.\nExploitation is driven by manipulating resource naming conventions when creating a ClusterCurator resource, which improperly triggers the automated creation of a cluster-scoped ClusterRoleBinding.\nThe impact of this flaw is severe, granting attackers broad permissions that encompass reading and manipulating sensitive secrets, orchestrating management actions across the infrastructure, and executing destructive operations such as deleting hosted clusters or node pools.\nRisk implications are high as multi-tenant isolation boundaries can be easily bypassed by unprivileged or localized users.\nAttacker capabilities require baseline namespace-local access to instantiate the malicious resource, after which automated controller logic handles the privilege escalation without requiring advanced exploitation vectors or network-based attacks.",
  "technicalDetails": "The root cause of the vulnerability resides in the validation and authorization logic of the cluster-curator-controller component, specifically how it handles incoming ClusterCurator resource creation requests.\nThe vulnerable component fails to properly validate and restrict user-supplied naming conventions against security boundaries when processing these resources.\nAn authenticated local user possessing only namespace-local permissions can initiate the attack flow by crafting and submitting a specifically named ClusterCurator resource.\nUpon processing the resource, the controller inadequately isolates the naming pattern and automatically provisions a cluster-scoped ClusterRoleBinding tied to the user-controlled parameters.\nBecause the resulting ClusterRoleBinding operates at the cluster scope rather than being restricted to the local namespace, it effectively grants elevated administrative privileges to the initiating entity.\nThe authentication and privilege requirements for exploitation are minimal; the attacker only needs localized, namespace-scoped access to create the initial ClusterCurator object.\nNo network exposure or remote exploitation is strictly required, as the vector is driven through standard API interactions available to authorized local principals.\nPost-exploitation impact includes complete compromise of the affected environment, enabling the adversary to access and manipulate cluster secrets, manage arbitrary cluster actions, and execute high-impact destructive tasks such as terminating hosted clusters and node pools."
}
CVE-2026-73269: Cluster Curator Privilege Escalation Vulnerability (CRITICAL Severity, CVSS: 9.9) - Sceawere