Privilege Escalation Vulnerability in Multicluster Engine for Kubernetes by Red Hat
CVE-2026-10059

9.1CRITICAL

What is CVE-2026-10059?

A security flaw was detected in the Multicluster Engine for Kubernetes related to its ClusterCurator controller. A tenant administrator with namespace-scoped privileges may create a namespaced ClusterCurator, unintentionally enabling them to generate a token for a ServiceAccount with extensive cluster-wide administrative powers. This vulnerability facilitates unauthorized privilege escalation, potentially leading to complete control over the Kubernetes cluster.

Affected Version(s)

multicluster engine for Kubernetes 2.1 1787201612

multicluster engine for Kubernetes 2.11 1787238383

multicluster engine for Kubernetes 2.6 1787264185

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
.