CVE
CVE-2026-73266
0field notes · 1digest CVSS 7.1
The verdict
An authenticated tenant in a Multicluster Engine (MCE) environment can manipulate ClusterClaim labels to force a cluster into another tenant's ManagedClusterSet. That lets the attacker push policies and workloads onto clusters they don't own. This requires an authenticated tenant account, so it's a cross-tenant boundary violation, not an unauthenticated attack.
Patch urgency · Patch this week
Daily digests