NPM · AUGUST 2026 · EARLY WARNING

cluster-curator-controller Privilege Escalation Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.9
Affected component
cluster-curator-controller (npm)
Patched version
Not yet available
CVE-2026-73269

An early warning has been issued for a critical vulnerability in the cluster-curator-controller component. This flaw allows a local user to escalate privileges from namespace-local access to cluster-wide control.

What happened

A flaw has been identified in the cluster-curator-controller component, tracked as CVE-2026-73269. This vulnerability permits a local user to create a ClusterCurator resource with a specific naming convention, triggering the creation of a cluster-scoped ClusterRoleBinding. This action elevates the user's privileges, granting them broad permissions including access to secrets, management of cluster actions, and deletion of hosted clusters or node pools.

The vulnerability was first flagged on 2026-08-12T20:17:53.793000+00:00. It is currently under investigation and has not been exploited in the wild. The CVSS score is 9.9, indicating a critical severity level.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cluster-curator-controller is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the cluster-curator-controller component, you may be affected. The specific version range is not yet published.

What should I do right now?

Upgrade to the latest version of cluster-curator-controller and review ClusterRoleBindings for any unauthorized changes. Monitor the primary sources for updates.

Is there an official fix available?

No official fix has been published yet. Continue to monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats