


Perceptive Security
SOC/SIEM Consultancy

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this v…
Published:
5 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 12:00:53
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access, Zero-Day Vulnerabilities
A critical privilege escalation vulnerability was discovered in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with only namespace-scoped privileges can exploit this flaw by creating a namespaced ClusterCurator resource. This inadvertently allows the attacker to mint a token for a ServiceAccount that holds cluster-wide administrative authority. The result is a full privilege escalation, granting the tenant administrator complete control over the entire Kubernetes cluster. This vulnerability poses a significant risk in multi-tenant Kubernetes environments where namespace isolation is expected to restrict administrative actions. The issue is tracked under CVE-2026-10059 and has been reported via Red Hat's security advisory and Bugzilla tracking systems.
Technical details
Mitigation steps:
Affected products:
Multicluster Engine for Kubernetes
ClusterCurator controller
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10059
https://access.redhat.com/security/cve/CVE-2026-10059
https://bugzilla.redhat.com/show_bug.cgi?id=2483187
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
