Privilege Escalation Vulnerability in Multicluster Engine for Kubernetes by Red Hat
CVE-2026-10059
9.1CRITICAL
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-10059?
A security flaw was detected in the Multicluster Engine for Kubernetes related to its ClusterCurator controller. A tenant administrator with namespace-scoped privileges may create a namespaced ClusterCurator, unintentionally enabling them to generate a token for a ServiceAccount with extensive cluster-wide administrative powers. This vulnerability facilitates unauthorized privilege escalation, potentially leading to complete control over the Kubernetes cluster.
Affected Version(s)
multicluster engine for Kubernetes 2.1 1787201612
multicluster engine for Kubernetes 2.11 1787238383
multicluster engine for Kubernetes 2.6 1787264185
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.