Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-19130
Red Hat multicluster engine for Kubernetes 2.10 — Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H L R C H N N 5.8 .0040 31.8 —
AFFECTED
Product Versions Fixed
multicluster engine for Kubernetes 2.10 unspecified 1787176886
multicluster engine for Kubernetes 2.11 unspecified 1787239595
multicluster engine for Kubernetes 2.17 unspecified 1786664288
multicluster engine for Kubernetes 2.6 unspecified 1787260821
multicluster engine for Kubernetes 2.8 unspecified 1787259099
multicluster engine for Kubernetes 2.9 unspecified 1787176716
TIMELINE
Aug 6 Reserved by redhat
Aug 12 Published (CNA: redhat)
Aug 25 PATCH SHIPPED — CVE-2026-19130 (Red Hat multicluster engine for Kubernetes 2.10). Fixed in multicluster engine for Kubernetes 2.10 1787176886.
Description
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 6, 2026 | Reserved | Reserved by redhat |
| August 12, 2026 | Published | Published (CNA: redhat) |
| August 25, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-19130 (Red Hat multicluster engine for Kubernetes 2.10). Fixed in multicluster engine for Kubernetes 2.10 1787176886. |
Affected
Affected products and packages — 6 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | multicluster engine for Kubernetes 2.10 | — | — | 1787176886 |
| Red Hat | multicluster engine for Kubernetes 2.11 | — | — | 1787239595 |
| Red Hat | multicluster engine for Kubernetes 2.17 | — | — | 1786664288 |
| Red Hat | multicluster engine for Kubernetes 2.6 | — | — | 1787260821 |
| Red Hat | multicluster engine for Kubernetes 2.8 | — | — | 1787259099 |
| Red Hat | multicluster engine for Kubernetes 2.9 | — | — | 1787176716 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19130 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.