VYPR

cluster-curator-controller

by Red Hat

CVEs (2)

  • CVE-2026-73269CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from…

  • CVE-2026-73268CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate…