CVE-2026-75569: Red Hat Multicluster Engine For Kubernetes 2.10

High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.

Affected products

  • Red Hat Multicluster Engine For Kubernetes 2.10: before 1787263075 (fixed in 1787263075)
  • Red Hat Multicluster Engine For Kubernetes 2.11: before 1787321579 (fixed in 1787321579)
  • Red Hat Multicluster Engine For Kubernetes 2.17: before 1787083639 (fixed in 1787083639)
  • Red Hat Multicluster Engine For Kubernetes 2.6: before 1787317415 (fixed in 1787317415)
  • Red Hat Multicluster Engine For Kubernetes 2.8: before 1787318262 (fixed in 1787318262)
  • Red Hat Multicluster Engine For Kubernetes 2.9: before 1787287150 (fixed in 1787287150)

Published 2026-08-19. Last modified 2026-09-29.