Description
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.
Published: 2026-08-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw was discovered in the clusterclaims-controller component of Multicluster Engine for Kubernetes. An authenticated tenant can manipulate ClusterClaim labels, allowing them to force a cluster to join a ManagedClusterSet that belongs to a different tenant. This unauthorized join enables the attacker to inject policies and workloads into other tenants’ clusters, potentially compromising confidentiality, integrity, and availability for those clusters.

Affected Systems

Red Hat Multicluster Engine for Kubernetes, version information not provided in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating a high severity level. EPSS information is unavailable, so no numeric estimate for exploitation probability is provided, and the issue is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated tenant, which limits exploitation to users with tenant‑level access. If exploited, the attacker could join a managed cluster to a different tenant’s ManagedClusterSet and subsequently deploy malicious policies and workloads on the target cluster.

Generated by OpenCVE AI on August 13, 2026 at 19:06 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply any available Red Hat patch or update to the Multicluster Engine for Kubernetes that addresses the clusterclaims‑controller label manipulation flaw.
  • Review and restrict tenant permissions so that tenants cannot modify ClusterClaim labels or assign them to ManagedClusterSets.
  • Disable or prevent cross‑tenant ManagedClusterSet joins by configuring the controller to reject ClusterClaim labels that refer to other tenants’ ManagedClusterSets.
  • Monitor ClusterClaim label changes and cluster join events for unauthorized activity.

Generated by OpenCVE AI on August 13, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join Clusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagated to managedcluster, enabling cross-tenant managedclusterset join

Wed, 26 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.10::el9
cpe:/a:redhat:multicluster_engine:2.6::el9
cpe:/a:redhat:multicluster_engine:2.8::el9
cpe:/a:redhat:multicluster_engine:2.9::el9
References

Tue, 25 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.17::el9
References

Tue, 25 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine cpe:/a:redhat:multicluster_engine:2.11::el9
References

Tue, 18 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat multicluster Engine For Kubernetes
Vendors & Products Redhat multicluster Engine For Kubernetes

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.
Title Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join
First Time appeared Redhat
Redhat multicluster Engine
Weaknesses CWE-441
CPEs cpe:/a:redhat:multicluster_engine
Vendors & Products Redhat
Redhat multicluster Engine
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Redhat Multicluster Engine Multicluster Engine For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-02T17:46:43.940Z

Reserved: 2026-08-11T17:22:38.645Z

Link: CVE-2026-73266

cve-icon Vulnrichment

Updated: 2026-08-18T01:25:38.586Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T17:17:35.713

Modified: 2026-08-26T05:18:17.173

Link: CVE-2026-73266

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T00:00:00Z

Links: CVE-2026-73266 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:15:03Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')