Description
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
Published: 2026-08-05
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A critically vulnerable mechanism exists in Red Hat Multicluster Engine for Kubernetes’s ClusterCurator controller that lets a tenant administrator with namespace‑scoped privileges create a localized ClusterCurator object. Doing so permits that administrator to mint a ServiceAccount token that grants cluster‑wide administrative authority, thereby enabling full control over the entire Kubernetes cluster. This flaw is a classic privilege‑escalation flaw (CWE‑266) where a lower‑level actor can acquire higher‑level capabilities without authorization.

Affected Systems

The vulnerability affects Red Hat Multicluster Engine for Kubernetes. No specific sub‑versions are listed; all supported instances of the product are potentially impacted. The product name and vendor are therefore Red Hat Multicluster Engine for Kubernetes.

Risk and Exploitability

The CVSS score of 9.1 marks this flaw as a high‑severity flaw. The EPSS score is currently unavailable, indicating there is no published data on the exploitation probability, and it is not listed in CISA’s KEV catalog. Because the vulnerability requires a tenant administrator with namespace‑level permissions, the likely attack vector is internal to the cluster, stemming from a compromised namespace administrator account or malicious activity executed by a user with such permissions. An attacker that can exercise these privileges can create the exploitable object, obtain a cluster‑wide token, and then freely manipulate any resource in the cluster. No public proof‑of‑concept or exploitation code is documented, but the path to privilege escalation is clear from the provided description. No effective workaround is available that satisfies Red Hat’s Product Security criteria; therefore the focus must remain on applying the patch or upgrading.

Generated by OpenCVE AI on August 5, 2026 at 10:51 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Contact Red Hat Security to obtain the latest approved fix or patch for Multicluster Engine for Kubernetes.
  • Upgrade the Multicluster Engine for Kubernetes installation to the patched version as soon as it becomes available.
  • Restrict or remove namespace‑level administrator rights and modify RBAC policies to disallow creation of ClusterCurator objects; audit for any existing ClusterCurator instances and revoke any cluster‑wide ServiceAccount tokens that may have been minted.
  • Red Hat indicates no effective workaround exists that satisfies the Product Security criteria; therefore rely on applying the patch or upgrading.

Generated by OpenCVE AI on August 5, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine cpe:/a:redhat:multicluster_engine:2.11::el9
References

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat multicluster Engine For Kubernetes
Vendors & Products Redhat multicluster Engine For Kubernetes

Wed, 05 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
Title Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token
First Time appeared Redhat
Redhat multicluster Engine
Weaknesses CWE-266
CPEs cpe:/a:redhat:multicluster_engine
Vendors & Products Redhat
Redhat multicluster Engine
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Multicluster Engine Multicluster Engine For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-25T18:41:25.384Z

Reserved: 2026-05-29T08:14:22.495Z

Link: CVE-2026-10059

cve-icon Vulnrichment

Updated: 2026-08-05T14:22:38.510Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T09:18:13.720

Modified: 2026-08-25T19:16:47.117

Link: CVE-2026-10059

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T08:35:00Z

Links: CVE-2026-10059 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T11:00:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment