CVE-2026-73268
CVE-2026-73268: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityCritical9.9
Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection
CVE-2026-73268Source published Source updated
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets. The vulnerability stems from insufficient validation of the `spec.install.overrideJob` field, enabling injection of malicious Job specifications that run with the controller's highly privileged ServiceAccount, potentially exposing…
- Affected products in this advisory
- multicluster engine for Kubernetes 2.11
- multicluster engine for Kubernetes 2.17
- multicluster engine for Kubernetes 2.6
- multicluster engine for Kubernetes 2.8
1 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- multicluster-engine/cluster-curator-controller-rhel9:1787201612
- multicluster-engine/cluster-curator-controller-rhel9:1787238383
- multicluster-engine/cluster-curator-controller-rhel9:1786750700
- multicluster-engine/cluster-curator-controller-rhel9:1787264185
8 more entries in the full advisory.
- Mitigation guidance
- To mitigate this issue, implement strict Role-Based Access Control (RBAC) policies to limit create and update permissions on `clustercurators.cluster.open-cluster-management.io` resources to trusted administrators only. This restricts the ability of less privileged tenants to exploit the vulnerability and escalate privileges within the Kubernetes environment.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.