PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10059 Red Hat CVE debrief

A flaw in the Multicluster Engine for Kubernetes ClusterCurator controller allows a tenant administrator with namespace-scoped privileges to create a namespaced ClusterCurator, inadvertently granting the ability to mint a token for a ServiceAccount with cluster-wide administrative authority, leading to privilege escalation. This vulnerability can have significant impacts on Kubernetes deployments, particularly those with multiple tenants or complex access control configurations. Defenders should prioritize verifying and mitigating this vulnerability, especially those managing Kubernetes clusters and tenant administrator access.

Vendor
Red Hat
Product
Multicluster Engine for Kubernetes
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-09-08
Advisory published
2026-08-05
Advisory updated
2026-09-08

Who should care

Tenant administrators, Kubernetes cluster administrators, and security teams responsible for managing and securing Kubernetes deployments should be aware of this vulnerability and take necessary actions to mitigate it.

Why it matters

CVE-2026-10059 is a critical vulnerability in the Multicluster Engine for Kubernetes that allows tenant administrators to escalate privileges, potentially leading to unauthorized access and lateral movement within the cluster. Defenders should prioritize verifying and mitigating this vulnerability, especially those managing Kubernetes clusters and tenant administrator access.

  • Potential privilege escalation for tenant administrators.
  • Increased risk of unauthorized access to Kubernetes clusters.
  • Possible lateral movement within the cluster.
  • Need for verification of affected versions and remediation.

Technical summary

The Multicluster Engine for Kubernetes ClusterCurator controller is vulnerable to a privilege escalation attack. A tenant administrator with namespace-scoped privileges can create a namespaced ClusterCurator, which grants the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This vulnerability can be exploited by creating a namespaced ClusterCurator, allowing the tenant administrator to gain elevated privileges and potentially leading to unauthorized access and lateral movement within the cluster.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially those managing Kubernetes clusters and tenant administrator access.

Recommended defensive actions

  • Verify and apply Red Hat's provided errata and security advisories for this CVE.
  • Restrict namespace-scoped privileges for tenant administrators.
  • Monitor and audit ClusterCurator controller activities.
  • Implement compensating controls to limit the impact of potential privilege escalation.
  • Review and update access control configurations for Kubernetes deployments.
  • Conduct regular security audits to detect and address potential vulnerabilities.
  • Track and verify the application of patches and mitigations for affected systems.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score and vector. Red Hat has provided errata and a security advisory for this CVE. The vulnerability affects the Multicluster Engine for Kubernetes ClusterCurator controller, and defenders should verify affected versions and apply necessary patches or mitigations. The NVD entry is currently Awaiting Analysis, and additional information may be available from Red Hat's errata and security advisories.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10059 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10059

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10059 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10059

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.