Impact
A flaw in the cluster-curator-controller allows a user with namespace-local access to inject a specially named ClusterCurator resource. This resource triggers the creation of a cluster-scoped ClusterRoleBinding that grants the requester broad authority, including reading and writing secrets, managing cluster actions, and deleting hosted clusters or node pools. The vulnerability is a classic privilege-escalation flaw based on mis‑configured role binding creation, categorized as CWE-269.
Affected Systems
The vulnerability impacts Red Hat Multi-cluster Engine for Kubernetes. No specific version information is supplied, so all released editions may be susceptible until a fix is applied.
Risk and Exploitability
The CVSS score of 9.9 places this issue in the critical range, and although the EPSS score is not available, the lack of a KEV listing does not diminish the potential for exploitation. The likely attack vector is through the Kubernetes API by a local user who can create ClusterCurator resources. If successful, the attacker obtains cluster-wide privileges that could compromise secrets and overall cluster integrity.
OpenCVE Enrichment