Vulnerability Description
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:59556
- https://access.redhat.com/errata/RHSA-2026:59557
- https://access.redhat.com/errata/RHSA-2026:59558
- https://access.redhat.com/errata/RHSA-2026:59559
- https://access.redhat.com/errata/RHSA-2026:59579
- https://access.redhat.com/errata/RHSA-2026:59593
- https://access.redhat.com/security/cve/CVE-2026-19130
- https://bugzilla.redhat.com/show_bug.cgi?id=2512105
FAQ
What is CVE-2026-19130?
CVE-2026-19130 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, coul...
How severe is CVE-2026-19130?
CVE-2026-19130 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19130?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.