cluster-curator-controller Privilege Escalation Vulnerability: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.9
- Affected component
- cluster-curator-controller (npm)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the cluster-curator-controller component. This flaw allows a local user to escalate privileges from namespace-local access to cluster-wide control.
What happened
A flaw has been identified in the cluster-curator-controller component, tracked as CVE-2026-73269. This vulnerability permits a local user to create a ClusterCurator resource with a specific naming convention, triggering the creation of a cluster-scoped ClusterRoleBinding. This action elevates the user's privileges, granting them broad permissions including access to secrets, management of cluster actions, and deletion of hosted clusters or node pools.
The vulnerability was first flagged on 2026-08-12T20:17:53.793000+00:00. It is currently under investigation and has not been exploited in the wild. The CVSS score is 9.9, indicating a critical severity level.
What to do about it
- Upgrade to the latest version of cluster-curator-controller as soon as it is available.
- Review all ClusterRoleBindings for any unauthorized changes.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
- No official fix has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
cluster-curator-controller is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the cluster-curator-controller component, you may be affected. The specific version range is not yet published.
What should I do right now?
Upgrade to the latest version of cluster-curator-controller and review ClusterRoleBindings for any unauthorized changes. Monitor the primary sources for updates.
Is there an official fix available?
No official fix has been published yet. Continue to monitor the primary sources for updates.