multicluster-engine/cluster-curator-controller-rhel9 vulnerabilities
CVEs whose affected-version data names the multicluster-engine/cluster-curator-controller-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-73269Critical· 9.9A flaw was found in the cluster-curator-controller component
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to…
CVE-2026-73268Critical· 9.9A flaw was found in the cluster-curator-controller component of multicluster engine (MCE)
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the Cre…
CVE-2026-10059Critical· 9.1A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertent…
CVE-2026-16242Critical· 9.4A flaw was found in the Konnectivity proxy-server configuration for hosted control planes
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not va…