← Back to search

CVE-2026-10059

9.1 CRITICAL

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows a tenant administrator with namespace-scoped privileges to exploit a vulnerability in the Multicluster Engine for Kubernetes ClusterCurator controller, leading to privilege escalation and full control over the cluster.
Exploitability
Exploitation requires specific privileges but is considered critical due to the severity of the resulting full cluster control.
Blast radius
If exploited, this vulnerability could have a significant impact on all resources within the affected Kubernetes cluster.
Prioritized remediation
Update the Multicluster Engine for Kubernetes ClusterCurator controller to the latest version that addresses this vulnerability.
privilege-escalationkubernetescluster-control

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-266

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.