Critical severity9.9NVD Advisory· Published Aug 12, 2026· Updated Sep 8, 2026
CVE-2026-73269
CVE-2026-73269
Description
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
8- access.redhat.com/errata/RHSA-2026:59556nvd
- access.redhat.com/errata/RHSA-2026:59557nvd
- access.redhat.com/errata/RHSA-2026:59558nvd
- access.redhat.com/errata/RHSA-2026:59559nvd
- access.redhat.com/errata/RHSA-2026:59579nvd
- access.redhat.com/errata/RHSA-2026:59593nvd
- access.redhat.com/security/cve/CVE-2026-73269nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.