PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19130 Red Hat CVE debrief

CVE-2026-19130 is a medium-severity vulnerability in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster and knowledge of a prior credential value could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure.

Vendor
Red Hat
Product
multicluster engine for Kubernetes 2.11
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-29
Advisory published
2026-08-12
Advisory updated
2026-09-29

Who should care

Defenders responsible for securing multicluster-engine (MCE) deployments, particularly those with high-risk or sensitive data, should assess their exposure and take steps to verify and secure the provider-credential-controller component.

Why it matters

CVE-2026-19130 is a medium-severity vulnerability in multicluster-engine (MCE) that allows unauthorized information disclosure. Defenders should prioritize verifying and securing the provider-credential-controller component, reviewing permissions on the hub cluster, and monitoring for suspicious activity related to credential rotation.

  • Verify and secure the provider-credential-controller component to prevent unauthorized information disclosure
  • Review and restrict permissions on the hub cluster to limit potential attack vectors
  • Monitor credential rotation activity for suspicious behavior
  • Apply Red Hat errata to affected systems

Technical summary

The provider-credential-controller component of multicluster-engine (MCE) is vulnerable to an authorization bypass attack. An attacker with specific permissions on the hub cluster and knowledge of a prior credential value could manipulate `copiedFrom` labels to intercept newly rotated provider credentials, leading to unauthorized information disclosure. This vulnerability allows defenders to prioritize verifying and securing the provider-credential-controller component, reviewing permissions on the hub cluster, and monitoring for suspicious activity related to credential rotation.

Defensive priority

Defenders should prioritize verifying and securing the provider-credential-controller component, reviewing permissions on the hub cluster, and monitoring for suspicious activity related to credential rotation.

Recommended defensive actions

  • Verify and secure the provider-credential-controller component
  • Review permissions on the hub cluster
  • Monitor for suspicious activity related to credential rotation
  • Apply Red Hat errata RHSA-2026:59556, RHSA-2026:59557, RHSA-2026:59558, RHSA-2026:59559, RHSA-2026:59579, and RHSA-2026:59593
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. Red Hat has provided several errata related to this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19130 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19130

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19130 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19130

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.