PatchSiren cyber security CVE debrief
CVE-2026-19130 Red Hat CVE debrief
CVE-2026-19130 is a medium-severity vulnerability in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster and knowledge of a prior credential value could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure.
- Vendor
- Red Hat
- Product
- multicluster engine for Kubernetes 2.11
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for securing multicluster-engine (MCE) deployments, particularly those with high-risk or sensitive data, should assess their exposure and take steps to verify and secure the provider-credential-controller component.
Why it matters
CVE-2026-19130 is a medium-severity vulnerability in multicluster-engine (MCE) that allows unauthorized information disclosure. Defenders should prioritize verifying and securing the provider-credential-controller component, reviewing permissions on the hub cluster, and monitoring for suspicious activity related to credential rotation.
- Verify and secure the provider-credential-controller component to prevent unauthorized information disclosure
- Review and restrict permissions on the hub cluster to limit potential attack vectors
- Monitor credential rotation activity for suspicious behavior
- Apply Red Hat errata to affected systems
Technical summary
The provider-credential-controller component of multicluster-engine (MCE) is vulnerable to an authorization bypass attack. An attacker with specific permissions on the hub cluster and knowledge of a prior credential value could manipulate `copiedFrom` labels to intercept newly rotated provider credentials, leading to unauthorized information disclosure. This vulnerability allows defenders to prioritize verifying and securing the provider-credential-controller component, reviewing permissions on the hub cluster, and monitoring for suspicious activity related to credential rotation.
Defensive priority
Defenders should prioritize verifying and securing the provider-credential-controller component, reviewing permissions on the hub cluster, and monitoring for suspicious activity related to credential rotation.
Recommended defensive actions
- Verify and secure the provider-credential-controller component
- Review permissions on the hub cluster
- Monitor for suspicious activity related to credential rotation
- Apply Red Hat errata RHSA-2026:59556, RHSA-2026:59557, RHSA-2026:59558, RHSA-2026:59559, RHSA-2026:59579, and RHSA-2026:59593
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. Red Hat has provided several errata related to this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19130 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19130
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19130 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19130
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59556
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59557
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59558
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59559
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59579
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59593
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-19130
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.