{"apiVersion":"1.0","identifier":"CVE-2026-73268","description":"A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller-s elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.","publishedAt":"2026-08-12T20:17:53","lastModifiedAt":"2026-08-25T21:17:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73268","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00468,"riskScore":1.03,"affectedProduct":"multicluster engine","affectedVersions":"unknown","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73268","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73268","en":"https://www.redsauce.net/en/cves/CVE-2026-73268","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73268","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73268","de":"https://www.redsauce.net/de/cves/CVE-2026-73268","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73268","el":"https://www.redsauce.net/el/cves/CVE-2026-73268"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73268"}}