An authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.
Multicluster Engine for Kubernetes
cve-2026-73266
kubernetes
privilege-escalation
multitenancy
cloud-native
vulnerability
cve-2026-66794
supply-chain
4t
1c
updated