{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cluster-curator-controller/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-73269"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cluster-curator-controller"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe cluster-curator-controller component contains a critical vulnerability (CVE-2026-73269) that enables local privilege escalation within Kubernetes-based environments. An attacker with existing namespace-local access can exploit this flaw by submitting a ClusterCurator resource object configured with a specific naming convention. The controller incorrectly processes this resource, resulting in the unauthorized creation of a cluster-scoped ClusterRoleBinding. This misconfiguration grants the attacker excessive permissions across the entire cluster, effectively elevating their access from a limited namespace scope to full administrative control. Impacted organizations are at risk of unauthorized access to sensitive secrets, modification of cluster configurations, and the potential destruction of hosted clusters or node pools. Because the exploit relies on the creation of legitimate K8s objects, defenders must focus on monitoring for anomalous resource naming patterns and unauthorized ClusterRoleBinding creation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes initial access to the cluster within a restricted namespace.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the cluster-curator-controller presence within the environment.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious ClusterCurator resource object with a target-specific naming convention.\u003c/li\u003e\n\u003cli\u003eAttacker applies the resource to their local namespace via \u003ccode\u003ekubectl apply\u003c/code\u003e or Kubernetes API calls.\u003c/li\u003e\n\u003cli\u003eThe cluster-curator-controller observes the new resource and attempts to process its configuration.\u003c/li\u003e\n\u003cli\u003eController logic fails to validate the resource name, causing it to escalate permissions.\u003c/li\u003e\n\u003cli\u003eController creates a ClusterRoleBinding with cluster-scoped administrative privileges.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the resulting ClusterRoleBinding to exfiltrate secrets or delete node pools.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full cluster-wide privilege escalation. Attackers can access and exfiltrate highly sensitive secrets, manipulate critical cluster resources, or delete hosted clusters and node pools, potentially causing complete infrastructure compromise and widespread service disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor Kubernetes audit logs for the creation of \u003ccode\u003eClusterRoleBinding\u003c/code\u003e resources.\u003c/li\u003e\n\u003cli\u003eAudit existing \u003ccode\u003eClusterCurator\u003c/code\u003e resources for anomalous naming conventions that deviate from documented naming standards.\u003c/li\u003e\n\u003cli\u003eImplement admission control policies to restrict the ability of low-privileged users to create or modify \u003ccode\u003eClusterCurator\u003c/code\u003e resources.\u003c/li\u003e\n\u003cli\u003eReview the \u003ccode\u003ecluster-curator-controller\u003c/code\u003e logs for unexpected resource handling errors related to \u003ccode\u003eCVE-2026-73269\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T20:49:57Z","date_published":"2026-08-12T20:49:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cluster-curator-privilege-escalation/","summary":"A vulnerability in the cluster-curator-controller component allows a local user to escalate privileges to cluster-wide control by submitting a malformed ClusterCurator resource.","title":"Local Privilege Escalation in cluster-curator-controller via ClusterCurator Resources","url":"https://feed.craftedsignal.io/briefs/2026-08-cluster-curator-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cluster-Curator-Controller","version":"https://jsonfeed.org/version/1.1"}