THREAT OPS › Threat News › [NVD] CVE-2026-10059 (CRITICAL 9.1) — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the abil
[NVD] CVE-2026-10059 (CRITICAL 9.1) — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the abil
CVE-2026-10059 CVSS: 9.1 CRITICAL Published: 2026-08-05T09:18:13.720
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with clus
Indicators of compromise
- CVE-2026-10059cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-10059