CVE-2026-10059: Incorrect Privilege Assignment in Red Hat multicluster engine for Kubernetes 2.1
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
AI Analysis
Technical Summary
This vulnerability exists in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator restricted to namespace-scoped privileges can exploit the flaw by creating a namespaced ClusterCurator resource. This action causes the controller to create cluster-scoped RBAC permissions for a ServiceAccount within the tenant's namespace. The tenant administrator can then mint a token for this ServiceAccount, which has cluster-wide administrative authority, resulting in privilege escalation from namespace-scoped to cluster-wide control. Red Hat has classified this as an important privilege escalation issue with a CVSS v3.1 score of 9.1. No patch or mitigation currently meets Red Hat's standards for deployment and stability.
Potential Impact
The vulnerability allows a namespace-scoped tenant administrator to escalate privileges to cluster-wide administrative authority. This grants the attacker full control over the Kubernetes cluster, including the ability to perform any administrative action. The impact includes complete compromise of confidentiality, integrity, and availability of the cluster resources.
Mitigation Recommendations
Red Hat currently states that no mitigation or patch is available that meets their criteria for ease of use, applicability, and stability. Users should monitor the Red Hat advisory for updates. Customers with a Technical Account Manager (TAM) may consult directly for guidance. Until a fix or mitigation is provided, restricting tenant administrator privileges and limiting access to the ClusterCurator resource may reduce exposure, but no official workaround is confirmed.
CVE-2026-10059: Incorrect Privilege Assignment in Red Hat multicluster engine for Kubernetes 2.1
Description
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
CVSS v3.1
Score 9.1critical
Affected software
Red Hat
multicluster engine for Kubernetes 2.1
Red Hat
multicluster engine for Kubernetes 2.11
Red Hat
multicluster engine for Kubernetes 2.6
Red Hat
multicluster engine for Kubernetes 2.8
Red Hat
multicluster engine for Kubernetes 2.9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator restricted to namespace-scoped privileges can exploit the flaw by creating a namespaced ClusterCurator resource. This action causes the controller to create cluster-scoped RBAC permissions for a ServiceAccount within the tenant's namespace. The tenant administrator can then mint a token for this ServiceAccount, which has cluster-wide administrative authority, resulting in privilege escalation from namespace-scoped to cluster-wide control. Red Hat has classified this as an important privilege escalation issue with a CVSS v3.1 score of 9.1. No patch or mitigation currently meets Red Hat's standards for deployment and stability.
Potential Impact
The vulnerability allows a namespace-scoped tenant administrator to escalate privileges to cluster-wide administrative authority. This grants the attacker full control over the Kubernetes cluster, including the ability to perform any administrative action. The impact includes complete compromise of confidentiality, integrity, and availability of the cluster resources.
Mitigation Recommendations
Red Hat currently states that no mitigation or patch is available that meets their criteria for ease of use, applicability, and stability. Users should monitor the Red Hat advisory for updates. Customers with a Technical Account Manager (TAM) may consult directly for guidance. Until a fix or mitigation is provided, restricting tenant administrator privileges and limiting access to the ClusterCurator resource may reduce exposure, but no official workaround is confirmed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-05-29T08:14:22.495Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-10059","vendor":"Red Hat"}]
Threat ID: 6a7331b4bf8831d539e4e97a
Added to database: 08/05/2026, 12:51:00 UTC
Last enriched: 08/12/2026, 15:42:58 UTC
Last updated: 09/17/2026, 22:01:32 UTC
Views: 78
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.