Red Hat disclosed CVE-2026-10059, an Important-severity privilege-escalation flaw in the ClusterCurator controller component of Multicluster Engine for Kubernetes. The vulnerability allows a tenant administrator with only namespace-scoped privileges to create a namespaced ClusterCurator, which causes the controller to create a cluster-installer ServiceAccount in the tenant namespace and bind it to cluster-wide curator privileges. Red Hat scored the issue CVSS 9.1 and mapped it to CWE-266 for incorrect privilege assignment.
Because the privileged ServiceAccount is created inside a tenant-controlled namespace, an attacker with namespace admin rights can mint a token for it and immediately inherit cluster-wide authority, effectively gaining full control of the Kubernetes cluster. Red Hat said the affected component is multicluster-engine/cluster-curator-controller-rhel9, reported that no mitigation meeting its product security criteria is currently available, and credited Christopher Lusk of North Echo Security Research with reporting the bug.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE record indicates that CVE-2026-10059 was newly received by secalert@redhat.com. The entry identifies the flaw as a CWE-266 privilege-assignment issue that can lead to full cluster control.
Red Hat published CVE-2026-10059 as an Important severity vulnerability affecting multicluster-engine/cluster-curator-controller-rhel9 in Multicluster Engine for Kubernetes. The advisory states that a tenant administrator with namespace-scoped privileges can escalate to cluster-wide administrative authority and that no mitigation meeting Red Hat's product security criteria is currently available.
Red Hat created Bugzilla entry 2483187 documenting a privilege-escalation issue in the Multicluster Engine for Kubernetes ClusterCurator controller. The report describes how a namespace-scoped tenant admin can mint a token for a controller-created ServiceAccount and gain cluster-wide curator authority.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.