Impact
A critically vulnerable mechanism exists in Red Hat Multicluster Engine for Kubernetes’s ClusterCurator controller that lets a tenant administrator with namespace‑scoped privileges create a localized ClusterCurator object. Doing so permits that administrator to mint a ServiceAccount token that grants cluster‑wide administrative authority, thereby enabling full control over the entire Kubernetes cluster. This flaw is a classic privilege‑escalation flaw (CWE‑266) where a lower‑level actor can acquire higher‑level capabilities without authorization.
Affected Systems
The vulnerability affects Red Hat Multicluster Engine for Kubernetes. No specific sub‑versions are listed; all supported instances of the product are potentially impacted. The product name and vendor are therefore Red Hat Multicluster Engine for Kubernetes.
Risk and Exploitability
The CVSS score of 9.1 marks this flaw as a high‑severity flaw. The EPSS score is currently unavailable, indicating there is no published data on the exploitation probability, and it is not listed in CISA’s KEV catalog. Because the vulnerability requires a tenant administrator with namespace‑level permissions, the likely attack vector is internal to the cluster, stemming from a compromised namespace administrator account or malicious activity executed by a user with such permissions. An attacker that can exercise these privileges can create the exploitable object, obtain a cluster‑wide token, and then freely manipulate any resource in the cluster. No public proof‑of‑concept or exploitation code is documented, but the path to privilege escalation is clear from the provided description. No effective workaround is available that satisfies Red Hat’s Product Security criteria; therefore the focus must remain on applying the patch or upgrading.
OpenCVE Enrichment