CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73268

criticalCVSS 9.9covered by 1 sourcefirst seen 2026-08-12
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.

⚡ Watch CVE-2026-73268

Get an email if CVE-2026-73268 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73268

CVE.org record

Embed the live status

CVE-2026-73268 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73268 status](https://www.csirts.com/badge/CVE-2026-73268)](https://www.csirts.com/cve/CVE-2026-73268)