CRITICALVulnerability

CVE-2026-73269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.

Properties

severity
CRITICAL
score
9.9
cve_id
CVE-2026-73269
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-12T20:17:53.793
last_modified
2026-08-25T21:17:45.707

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73269 — Ninja Signal Threat Intelligence | Ninja Signal