PatchSiren cyber security CVE debrief
CVE-2026-73269 Red Hat CVE debrief
A local user can create a ClusterCurator resource to escalate privileges from namespace-local access to cluster-wide control, granting broad permissions. This vulnerability affects the cluster-curator-controller component, allowing privilege escalation through a specific naming convention. It has a critical CVSS score of 9.9 and requires immediate attention. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
- Vendor
- Red Hat
- Product
- multicluster engine for Kubernetes 2.11
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-25
Who should care
Administrators and users of cluster-curator-controller component, especially those with local access to the system, should be aware of the potential privilege escalation vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
A flaw in the cluster-curator-controller component allows a local user to create a ClusterCurator resource with a specific naming convention, triggering the creation of a cluster-scoped ClusterRoleBinding. This enables privilege escalation from namespace-local access to cluster-wide control, granting broad permissions including access and manipulation of secrets, management of cluster actions, and deletion of hosted clusters or node pools. The vulnerability has a critical CVSS score of 9.9 and requires immediate attention.
Defensive priority
High priority due to critical CVSS score of 9.9 and potential for privilege escalation.
Recommended defensive actions
- Inventory cluster-curator-controller component for potential exposure
- Restrict access to ClusterCurator resource creation
- Monitor for suspicious activity related to ClusterRoleBinding creation
- Apply vendor remediation when available
- Implement compensating controls to limit cluster-wide access
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from Redhat suggests a flaw in the cluster-curator-controller component. Further analysis is needed to determine the full scope of the vulnerability. The vulnerability allows a local user to create a ClusterCurator resource with a specific naming convention, triggering the creation of a cluster-scoped ClusterRoleBinding. This enables privilege escalation from namespace-local access to cluster-wide control, granting broad permissions including access and manipulation of secrets, management of cluster actions, and deletion of hosted clusters or node pools. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73269 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73269
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73269 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73269
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59556
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59593
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-73269
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.