Skip to main content
EPSS 0.6%top 53%

CVE-2026-75569: Reliance on Insufficiently Trustworthy Component in Red Hat multicluster engine for Kubernetes 2.10

0
High
Published: 08/19/2026 (08/19/2026, 20:47:45 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: multicluster engine for Kubernetes 2.10

Description

CVE-2026-75569 is a supply chain vulnerability in the multicluster engine for Kubernetes (mce-operator-bundle) where the build process fetches and executes scripts from a remote repository without integrity checks. This allows a malicious actor with write access to the remote repository to inject arbitrary code during the build, potentially compromising the build process and the integrity of distributed software. The vulnerability affects versions prior to 2.9.7 and 2.10.6. There are no direct runtime mitigations since the issue is in the build-time process. Red Hat has released updated images in version 2.9.7 to address this issue.

CVSS v3.1

Score 7.7high

Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Affected software

Affected versions
>=2.1 <2.9.7>=2.10 <2.10.6

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:31:18 UTC

Technical Analysis

The multicluster engine for Kubernetes provides centralized management for multiple Kubernetes clusters. CVE-2026-75569 is a vulnerability in the mce-operator-bundle build process where build scripts are fetched from a mutable remote repository branch without commit pinning or signature verification. This lack of integrity checks allows an attacker with write access to the remote repository to inject and execute arbitrary code during the build, compromising the build process and potentially the integrity of the resulting software. The vulnerability introduces a supply chain risk and is rated as Important by Red Hat. The issue affects versions >=2.1 <2.9.7 and >=2.10 <2.10.6. Red Hat has released version 2.9.7 with security fixes. No runtime mitigations are available because the vulnerability is in the build process itself.

Potential Impact

The vulnerability allows a malicious actor with write access to the remote repository used in the build process to inject arbitrary code, compromising the build integrity and potentially leading to distribution of malicious software. This impacts the trustworthiness of the multicluster engine for Kubernetes software delivered by Red Hat. There is no indication of active exploitation in the wild. The impact is on confidentiality and integrity of the software supply chain, with no direct availability impact.

Mitigation Recommendations

This vulnerability resides in the build process of the mce-operator-bundle and cannot be mitigated by runtime configuration changes. Users should upgrade to Red Hat multicluster engine for Kubernetes version 2.9.7 or later, which includes security fixes addressing this issue. Follow Red Hat's documentation for installing updated images. No direct operational mitigations exist for deployed products. Monitoring for updated advisories from Red Hat is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:59638
Cve Count
1
State
PUBLISHED

Threat ID: 6a8effebacd9273b49080947

Added to database: 08/26/2026, 15:02:03 UTC

Last enriched: 09/29/2026, 21:31:18 UTC

Last updated: 10/10/2026, 18:48:22 UTC

Views: 60

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses