PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73266 Red Hat CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T17:17:35.713Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This vulnerability affects the clusterclaims-controller component of Multicluster Engine (MCE), allowing authenticated tenants to manipulate ClusterClaim labels and potentially inject policies and workloads into other tenants' clusters by forcing clusters to join ManagedClusterSets belonging to other tenants. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Administrators and security teams managing MCE deployments, especially in multi-tenant environments, should review cluster configurations, restrict ClusterClaim label manipulation permissions, and monitor for unauthorized cluster membership changes. Evidence is limited to CVE and NVD data, so defenders should verify cluster configurations and review ClusterClaim label controls.

Vendor
Red Hat
Product
multicluster engine for Kubernetes 2.11
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-08-25
Advisory published
2026-08-13
Advisory updated
2026-08-25

Who should care

Administrators and security teams managing Multicluster Engine (MCE) deployments, especially those with multi-tenant environments, should be aware of this vulnerability and take steps to mitigate its risks. Operators and platform teams responsible for cluster configurations and security should review and restrict ClusterClaim label manipulation permissions.

Technical summary

The clusterclaims-controller component of Multicluster Engine (MCE) is vulnerable to exploitation by authenticated tenants. By manipulating ClusterClaim labels, a tenant can force a cluster to join a ManagedClusterSet belonging to another tenant. This unauthorized access could enable the injection of policies and workloads into other tenants' clusters. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Affected product deployments should be reviewed for exposure.

Defensive priority

Authenticated tenants can exploit this vulnerability to force clusters to join ManagedClusterSets belonging to other tenants, potentially enabling policy and workload injection.

Recommended defensive actions

  • Review and restrict ClusterClaim label manipulation permissions for authenticated tenants
  • Implement monitoring for unauthorized cluster membership changes
  • Verify and enforce proper isolation between ManagedClusterSets
  • Apply vendor-provided patches or updates when available
  • Conduct regular security audits of cluster configurations
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs for exposed assets

Evidence notes

The clusterclaims-controller component of Multicluster Engine (MCE) is vulnerable to manipulation of ClusterClaim labels by authenticated tenants, potentially allowing unauthorized access and policy injection. Evidence is limited to CVE and NVD data. Defenders should verify cluster configurations, review ClusterClaim label controls, and monitor for suspicious cluster membership changes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73266 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73266

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73266 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73266

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.