Description
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Published: 2026-08-12
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization bypass flaw in the provider‑credential‑controller component of Red Hat Multicluster Engine for Kubernetes allows an attacker with specific hub‑cluster permissions and knowledge of a prior credential value to manipulate copiedFrom labels. By doing so the attacker can intercept newly rotated provider credentials, resulting in unauthorized disclosure of sensitive credential information.

Affected Systems

Red Hat Multicluster Engine for Kubernetes. No specific affected version range is provided in the advisory.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting a low to moderate likelihood of exploitation. Successful exploitation requires deliberate permission settings on the hub cluster and prior knowledge of a credential value, limiting the attack surface but still enabling an attacker to gain confidential credentials if they can craft the copiedFrom labels.

Generated by OpenCVE AI on August 13, 2026 at 02:19 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat patch for Multicluster Engine that fixes the provider‑credential‑controller flaw.
  • Remove or tighten permissions for users on the hub cluster so they cannot manipulate provider‑credential‑controller objects.
  • Configure the cluster to disallow or audit copiedFrom labels on provider credentials to prevent credential leakage.

Generated by OpenCVE AI on August 13, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.10::el9
cpe:/a:redhat:multicluster_engine:2.6::el9
cpe:/a:redhat:multicluster_engine:2.8::el9
cpe:/a:redhat:multicluster_engine:2.9::el9
References

Tue, 25 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.17::el9
References

Tue, 25 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine cpe:/a:redhat:multicluster_engine:2.11::el9
References

Fri, 14 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 13 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat multicluster Engine For Kubernetes
Vendors & Products Redhat multicluster Engine For Kubernetes

Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Title Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization
First Time appeared Redhat
Redhat multicluster Engine
Weaknesses CWE-639
CPEs cpe:/a:redhat:multicluster_engine
Vendors & Products Redhat
Redhat multicluster Engine
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Multicluster Engine Multicluster Engine For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-26T04:18:16.904Z

Reserved: 2026-08-06T15:55:10.000Z

Link: CVE-2026-19130

cve-icon Vulnrichment

Updated: 2026-08-14T22:14:01.325Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T21:17:37.703

Modified: 2026-08-26T05:18:06.530

Link: CVE-2026-19130

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-12T18:00:00Z

Links: CVE-2026-19130 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:30:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key