THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73267 (HIGH 7.7) — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any Ma

[NVD] CVE-2026-73267 (HIGH 7.7) — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any Ma

mednvdPublished 2026-08-21

CVE-2026-73267 CVSS: 7.7 HIGH Published: 2026-08-21T03:16:39.080

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's local-cluster or oth

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73267