Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-73266

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

EPSS

Процентиль: 6%
0.0016
Низкий

7.1 High

CVSS3

Дефекты

CWE-441

Связанные уязвимости

CVSS3: 7.1
redhat
8 дней назад

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

CVSS3: 7.1
github
6 дней назад

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

EPSS

Процентиль: 6%
0.0016
Низкий

7.1 High

CVSS3

Дефекты

CWE-441