CVE-2026-73267
- EPSS -
- Veröffentlicht 21.08.2026 02:43:36
- Zuletzt bearbeitet 21.08.2026 03:16:39
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenan...
CVE-2026-75569
- EPSS 0.29%
- Veröffentlicht 19.08.2026 20:47:45
- Zuletzt bearbeitet 20.08.2026 14:17:58
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to...
CVE-2026-66794
- EPSS 0.32%
- Veröffentlicht 19.08.2026 17:30:07
- Zuletzt bearbeitet 21.08.2026 20:16:39
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipula...
CVE-2026-66795
- EPSS 0.22%
- Veröffentlicht 17.08.2026 20:45:33
- Zuletzt bearbeitet 18.08.2026 16:18:14
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerab...
CVE-2026-73266
- EPSS 0.16%
- Veröffentlicht 13.08.2026 16:36:45
- Zuletzt bearbeitet 18.08.2026 02:17:28
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet...
CVE-2026-19130
- EPSS 0.18%
- Veröffentlicht 12.08.2026 20:46:21
- Zuletzt bearbeitet 14.08.2026 23:16:32
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. B...
CVE-2026-73268
- EPSS 0.37%
- Veröffentlicht 12.08.2026 19:05:12
- Zuletzt bearbeitet 14.08.2026 19:07:46
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() func...
CVE-2026-73269
- EPSS 0.23%
- Veröffentlicht 12.08.2026 19:05:05
- Zuletzt bearbeitet 14.08.2026 19:07:46
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate the...
CVE-2026-10059
- EPSS 0.27%
- Veröffentlicht 05.08.2026 09:18:13
- Zuletzt bearbeitet 06.08.2026 15:37:22
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the...
CVE-2026-17107
- EPSS 0.35%
- Veröffentlicht 24.07.2026 18:56:05
- Zuletzt bearbeitet 25.08.2026 05:17:20
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first re...