AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73269

CRITICAL · CVSS 9.9 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the cluster-curator-controller component, allowing local users to escalate their privileges to cluster-wide access by creating a specially named ClusterCurator resource. This privilege escalation can lead to unauthorized access to sensitive secrets, manipulation of cluster actions, and potential deletion of clusters or node pools. Organizations utilizing this component should prioritize immediate remediation to mitigate the risk of significant security breaches.

CVE
CVE-2026-73269
Severity
CRITICAL
CVSS
9.9
EPSS
0.23%

Original NVD Description

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.