Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

multicluster engine for Kubernetes 2.10 — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in multicluster engine for Kubernetes 2.10, with AI-generated Chinese analysis, references, and POCs.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-73267 Clusterclaims-controller: clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no ownership check CWE-602 7.7 High 2026-08-21
CVE-2026-75569 Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mutable stolostron/release@master CWE-829 7.7 High 2026-08-19
CVE-2026-66794 Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route CWE-918 9.3 Critical 2026-08-19
CVE-2026-66795 Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity CWE-295 9.1 Critical 2026-08-17
CVE-2026-73266 Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join CWE-441 7.1 High 2026-08-13
CVE-2026-19130 Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization CWE-639 5.8 Medium 2026-08-12
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection CWE-94 9.9 Critical 2026-08-12
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa CWE-269 9.9 Critical 2026-08-12
CVE-2026-10059 Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token CWE-266 9.1 Critical 2026-08-05
CVE-2026-17107 Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster CWE-441 8.5 High 2026-07-24
CVE-2026-16242 Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates CWE-306 9.4 Critical 2026-07-20
CVE-2026-4740 Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation CWE-295 8.2 High 2026-04-07

All 12 known CVE vulnerabilities affecting multicluster engine for Kubernetes 2.10 with full Chinese analysis, references, and POCs where available.