THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-10059 (CRITICAL 9.1) — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the abil

[NVD] CVE-2026-10059 (CRITICAL 9.1) — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the abil

lownvdPublished 2026-08-05

CVE-2026-10059 CVSS: 9.1 CRITICAL Published: 2026-08-05T09:18:13.720

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with clus

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-10059