A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.10::el9 cpe:/a:redhat:multicluster_engine:2.6::el9 cpe:/a:redhat:multicluster_engine:2.8::el9 cpe:/a:redhat:multicluster_engine:2.9::el9 |
|
| References |
|
Tue, 25 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.17::el9 | |
| References |
|
Tue, 25 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.11::el9 | |
| References |
|
Fri, 14 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 13 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat multicluster Engine For Kubernetes
|
|
| Vendors & Products |
Redhat multicluster Engine For Kubernetes
|
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected. | |
| Title | Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-08-12T20:46:21.305Z
Updated: 2026-09-08T12:17:53.816Z
Reserved: 2026-08-06T15:55:10.000Z
Link: CVE-2026-19130
Updated: 2026-08-14T22:14:01.325Z
Status : Awaiting Analysis
Published: 2026-08-12T21:17:37.703
Modified: 2026-09-08T13:17:18.373
Link: CVE-2026-19130