CVE-2026-73266 is a vulnerability in Red Hat Multicluster Engine
Published on August 13, 2026
Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.
Vulnerability Analysis
CVE-2026-73266 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 1 day later.
Weakness Type
What is a Confused Deputy Vulnerability?
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
CVE-2026-73266 has been classified to as a Confused Deputy vulnerability or weakness.
Products Associated with CVE-2026-73266
Want to know whenever a new CVE is published for Red Hat Multicluster Engine? stack.watch will email you.