{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-73266/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-73266"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Multicluster Engine for Kubernetes"],"_cs_severities":["high"],"_cs_tags":["cve-2026-73266","kubernetes","privilege-escalation","multitenancy","cloud-native"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA security flaw (CVE-2026-73266) exists within the clusterclaims-controller component of Red Hat Multicluster Engine (MCE) for Kubernetes. This vulnerability, categorized as a 'Confused Deputy' (CWE-441), allows an authenticated tenant within a multi-tenant environment to manipulate ClusterClaim labels. By improperly influencing the controller's logic, an attacker can force a cluster to join a ManagedClusterSet belonging to a different tenant. This unauthorized association breaks tenant isolation boundaries, providing the attacker the ability to push malicious policies or workloads into another tenant's environment. The vulnerability has a CVSS 3.1 score of 7.1, highlighting the potential for significant cross-tenant privilege escalation and impact on cluster integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates as a legitimate, lower-privileged tenant within the shared Multicluster Engine environment.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the Kubernetes API to modify ClusterClaim resource objects.\u003c/li\u003e\n\u003cli\u003eAttacker injects or updates specific ClusterClaim labels designed to target a victim ManagedClusterSet.\u003c/li\u003e\n\u003cli\u003eThe vulnerable clusterclaims-controller observes the modified labels.\u003c/li\u003e\n\u003cli\u003eDue to insufficient validation, the controller incorrectly associates the attacker-controlled cluster with the victim's ManagedClusterSet.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the cross-tenant membership to perform administrative actions.\u003c/li\u003e\n\u003cli\u003eAttacker executes API calls to push unauthorized policies or malicious container workloads into the victim's cluster.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete breach of multi-tenant isolation. Attackers can gain control over clusters they do not own, leading to unauthorized workload deployment, policy manipulation, and potential exfiltration of sensitive data residing in the victim's managed cluster environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security operations and platform teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply the latest security patches for the Multicluster Engine for Kubernetes provided by Red Hat to resolve CVE-2026-73266.\u003c/li\u003e\n\u003cli\u003eAudit Kubernetes API audit logs for unusual modification patterns involving ClusterClaim resources where the user context does not match the target ClusterSet namespace.\u003c/li\u003e\n\u003cli\u003eImplement restrictive Kubernetes Admission Controllers (e.g., OPA Gatekeeper or Kyverno) to enforce strict validation of label sets on ClusterClaim resources, preventing users from modifying critical system labels.\u003c/li\u003e\n\u003cli\u003eReview RBAC policies to ensure that tenants are restricted from modifying ClusterClaim labels that influence cluster-level scheduling or grouping.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T18:56:27Z","date_published":"2026-08-13T18:56:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mce-confused-deputy/","summary":"An authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.","title":"Red Hat Multicluster Engine Confused Deputy Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-mce-confused-deputy/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-73266","version":"https://jsonfeed.org/version/1.1"}