PatchSiren cyber security CVE debrief
CVE-2026-10059 Red Hat CVE debrief
A flaw in the Multicluster Engine for Kubernetes ClusterCurator controller allows a tenant administrator with namespace-scoped privileges to create a namespaced ClusterCurator, inadvertently granting the ability to mint a token for a ServiceAccount with cluster-wide administrative authority, leading to privilege escalation. This vulnerability can have significant impacts on Kubernetes deployments, particularly those with multiple tenants or complex access control configurations. Defenders should prioritize verifying and mitigating this vulnerability, especially those managing Kubernetes clusters and tenant administrator access.
- Vendor
- Red Hat
- Product
- Multicluster Engine for Kubernetes
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-09-08
Who should care
Tenant administrators, Kubernetes cluster administrators, and security teams responsible for managing and securing Kubernetes deployments should be aware of this vulnerability and take necessary actions to mitigate it.
Why it matters
CVE-2026-10059 is a critical vulnerability in the Multicluster Engine for Kubernetes that allows tenant administrators to escalate privileges, potentially leading to unauthorized access and lateral movement within the cluster. Defenders should prioritize verifying and mitigating this vulnerability, especially those managing Kubernetes clusters and tenant administrator access.
- Potential privilege escalation for tenant administrators.
- Increased risk of unauthorized access to Kubernetes clusters.
- Possible lateral movement within the cluster.
- Need for verification of affected versions and remediation.
Technical summary
The Multicluster Engine for Kubernetes ClusterCurator controller is vulnerable to a privilege escalation attack. A tenant administrator with namespace-scoped privileges can create a namespaced ClusterCurator, which grants the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This vulnerability can be exploited by creating a namespaced ClusterCurator, allowing the tenant administrator to gain elevated privileges and potentially leading to unauthorized access and lateral movement within the cluster.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially those managing Kubernetes clusters and tenant administrator access.
Recommended defensive actions
- Verify and apply Red Hat's provided errata and security advisories for this CVE.
- Restrict namespace-scoped privileges for tenant administrators.
- Monitor and audit ClusterCurator controller activities.
- Implement compensating controls to limit the impact of potential privilege escalation.
- Review and update access control configurations for Kubernetes deployments.
- Conduct regular security audits to detect and address potential vulnerabilities.
- Track and verify the application of patches and mitigations for affected systems.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score and vector. Red Hat has provided errata and a security advisory for this CVE. The vulnerability affects the Multicluster Engine for Kubernetes ClusterCurator controller, and defenders should verify affected versions and apply necessary patches or mitigations. The NVD entry is currently Awaiting Analysis, and additional information may be available from Red Hat's errata and security advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-10059 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-10059
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-10059 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10059
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59556
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59557
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59558
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59559
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59579
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-10059
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.