CVE-2026-19130 - Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization
Brief
CVE ID : CVE-2026-19130
Published : Aug. 12, 2026, 8:46 p. m.
- 18 minutes ago
Description : A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure.
This allows access to sensitive credentials that should otherwise be protected.
Severity: 5.8
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
