CVE-2026-10059: Red Hat Multicluster Engine For Kubernetes 2.1

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.

Affected products

  • Red Hat Multicluster Engine For Kubernetes 2.1: before 1787201612 (fixed in 1787201612)
  • Red Hat Multicluster Engine For Kubernetes 2.11: before 1787238383 (fixed in 1787238383)
  • Red Hat Multicluster Engine For Kubernetes 2.6: before 1787264185 (fixed in 1787264185)
  • Red Hat Multicluster Engine For Kubernetes 2.8: before 1787259011 (fixed in 1787259011)
  • Red Hat Multicluster Engine For Kubernetes 2.9: before 1787201646 (fixed in 1787201646)

Published 2026-08-05. Last modified 2026-09-08.