PatchDayAlert

CVE

CVE-2026-73266

0field notes · 1digest CVSS 7.1

The verdict

An authenticated tenant in a Multicluster Engine (MCE) environment can manipulate ClusterClaim labels to force a cluster into another tenant's ManagedClusterSet. That lets the attacker push policies and workloads onto clusters they don't own. This requires an authenticated tenant account, so it's a cross-tenant boundary violation, not an unauthenticated attack.

Patch urgency · Patch this week


Daily digests