CVE-2026-73268Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-13: 1Mentions · 2026-08-17: 2Mentions · 2026-08-20: 1Patch / Workaround · 2026-08-17: 2Technical Details · 2026-08-13: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-20: 108-1308-1708-20
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-131
Disclosure1
2026-08-172
Patch2
2026-08-201
Disclosure1
Full discourse4 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: Red Hat has patched two CVSS 9.9 remote code execution flaws in Red Hat Advanced Cluster Management (RHACM). Tracked as CVE-2026-72526 and CVE-2026-73268, both vulnerabilities can potentially lead to remote code execution in affected environments. Admins should review Red Hat’s security advisories and apply the available fixes. #RedHat #RHACM #CVE #RCE #CyberSecurity #Kubernetes #CloudSecurity #Infosec

    Post summary

    Red Hat has released patches for two high‑severity CVSS 9.9 remote code execution vulnerabilities (CVE‑2026‑72526 and CVE‑2026‑73268) in RHACM; administrators should update via the vendor’s advisories.

    2501651.8K
    1.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Red Hat fixes RHACM remote code execution flaws, including CVE-2026-72526 and CVE-2026-73268, both CVSS 9.9. See patch and mitigation steps. #RHACM #RedHat #Kubernetes #ArgoCD #RCE #CVE #CyberSecurity #InfoSec https://securityonline.info/rhacm-remote-code-execution-flaws/

    Post summary

    Red Hat has published patches for two high‑severity remote code execution vulnerabilities (CVE‑2026‑72526 and CVE‑2026‑73268) in RHACM, providing mitigation steps.

    01031451
    13.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Red Hat RHACM/MCEに深刻な5件の脆弱性 CVSS 9.9、管理クラスタで任意コード実行・権限昇格の恐れ(CVE-2026-72526,CVE-2026-73268)他 https://rocket-boys.co.jp/security-measures-lab/redhat-rhacm-mce-vulnerabilities-cve-2026-72526-73268/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    The post announces five high‑severity CVEs for Red Hat RHACM/MCE, noting CVSS 9.9 and risks of arbitrary code execution and privilege escalation, but does not provide PoC, patches, or evidence of active exploitation.

    00001179
    550 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · ☁️ Kubernetes Security · 12–13 August 2026 🎯 Red Hat discloses CVSS 9.9 Kubernetes privilege-escalation vulnerability Red Hat has disclosed CVE-2026-73268, a critical vulnerability affecting the Multicluster Engine for Kubernetes. A tenant with relatively limited permissions over ClusterCurator resources could exploit insufficient input validation to cause attacker-controlled workloads to execute using the controller's highly privileged service account. The result can be arbitrary code execution, privilege escalation and potential access to cluster-wide secrets. Red Hat gives the vulnerability a near-maximum CVSS score of 9.9. 🔗 Source: Red Hat Product Security #RedHat #Kubernetes #OpenShift #PrivilegeEscalation #CloudSecurity

    Post summary

    Red Hat disclosed CVE‑2026‑73268, a critical privilege‑escalation vulnerability in its Multicluster Engine for Kubernetes, enabling arbitrary code execution via insufficient validation of ClusterCurator resources. No PoC, exploit, or patch details were included.

    0000043
    53 followersView on X

Explore more