CVE-2026-75569: Reliance on Insufficiently Trustworthy Component in Red Hat multicluster engine for Kubernetes 2.10
Description
CVE-2026-75569 is a supply chain vulnerability in the multicluster engine for Kubernetes (mce-operator-bundle) where the build process fetches and executes scripts from a remote repository without integrity checks. This allows a malicious actor with write access to the remote repository to inject arbitrary code during the build, potentially compromising the build process and the integrity of distributed software. The vulnerability affects versions prior to 2.9.7 and 2.10.6. There are no direct runtime mitigations since the issue is in the build-time process. Red Hat has released updated images in version 2.9.7 to address this issue.
CVSS v3.1
Score 7.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The multicluster engine for Kubernetes provides centralized management for multiple Kubernetes clusters. CVE-2026-75569 is a vulnerability in the mce-operator-bundle build process where build scripts are fetched from a mutable remote repository branch without commit pinning or signature verification. This lack of integrity checks allows an attacker with write access to the remote repository to inject and execute arbitrary code during the build, compromising the build process and potentially the integrity of the resulting software. The vulnerability introduces a supply chain risk and is rated as Important by Red Hat. The issue affects versions >=2.1 <2.9.7 and >=2.10 <2.10.6. Red Hat has released version 2.9.7 with security fixes. No runtime mitigations are available because the vulnerability is in the build process itself.
Potential Impact
The vulnerability allows a malicious actor with write access to the remote repository used in the build process to inject arbitrary code, compromising the build integrity and potentially leading to distribution of malicious software. This impacts the trustworthiness of the multicluster engine for Kubernetes software delivered by Red Hat. There is no indication of active exploitation in the wild. The impact is on confidentiality and integrity of the software supply chain, with no direct availability impact.
Mitigation Recommendations
This vulnerability resides in the build process of the mce-operator-bundle and cannot be mitigated by runtime configuration changes. Users should upgrade to Red Hat multicluster engine for Kubernetes version 2.9.7 or later, which includes security fixes addressing this issue. Follow Red Hat's documentation for installing updated images. No direct operational mitigations exist for deployed products. Monitoring for updated advisories from Red Hat is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:59638
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a8effebacd9273b49080947
Added to database: 08/26/2026, 15:02:03 UTC
Last enriched: 09/29/2026, 21:31:18 UTC
Last updated: 10/10/2026, 18:48:22 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.