Red Hat disclosed CVE-2026-73268, an Important-severity flaw in the cluster-curator-controller component of Multicluster Engine for Kubernetes that can let a tenant escalate privileges to the controller’s level. The issue stems from the CreateJob() function improperly unmarshaling user-controlled data from spec.install.overrideJob into a Kubernetes Job without validating dangerous fields, enabling arbitrary Job specification injection by users who can create or update ClusterCurator resources.
Successful exploitation can cause the injected Job to run under the controller’s privileged ServiceAccount, potentially allowing arbitrary code execution, access to cluster-wide secrets, and control over managed cluster resources. Red Hat scored the bug 9.9 CVSS v3.1 and linked it to CWE-94; affected software includes multicluster-engine/cluster-curator-controller-rhel9. Recommended mitigations include applying vendor fixes, tightening RBAC so only trusted administrators can manage clustercurators.cluster.open-cluster-management.io, and reviewing controller privileges and validation controls around Job creation.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Maintainers of the open-cluster-management cluster-curator-controller repository committed a security fix labeled "security: patch CVE-2026-73268 and CVE-2026-73269" in commit 37e92be. The change documents remediation work for both vulnerabilities in the project’s controllers.
Red Hat disclosed CVE-2026-73268 affecting the cluster-curator-controller component of Multicluster Engine for Kubernetes. The vulnerability allows a tenant with create or update permissions on ClusterCurator resources to inject an arbitrary Kubernetes Job via spec.install.overrideJob, leading to code execution and privilege escalation with the controller's elevated privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.