{"apiVersion":"1.0","identifier":"CVE-2026-73269","description":"A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.","publishedAt":"2026-08-12T20:17:53","lastModifiedAt":"2026-08-25T21:17:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73269","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00332,"riskScore":1.02,"affectedProduct":"multicluster engine","affectedVersions":"unknown","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73269","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73269","en":"https://www.redsauce.net/en/cves/CVE-2026-73269","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73269","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73269","de":"https://www.redsauce.net/de/cves/CVE-2026-73269","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73269","el":"https://www.redsauce.net/el/cves/CVE-2026-73269"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73269"}}