{
  "threat_severity" : "Important",
  "public_date" : "2026-08-05T08:35:00Z",
  "bugzilla" : {
    "description" : "cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token",
    "id" : "2483187",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2483187"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-266",
  "details" : [ "A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.", "A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster." ],
  "statement" : "This is an Important privilege escalation flaw in Multicluster Engine for Kubernetes. A namespace-scoped tenant administrator can achieve cluster-wide administrative authority by leveraging the ClusterCurator controller's creation of cluster-scoped RBAC for a ServiceAccount within a tenant-controlled namespace. This allows the tenant to mint a token for the controller-created ServiceAccount, granting full control over the cluster.",
  "acknowledgement" : "Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "multicluster engine for Kubernetes 2.1",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59557",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.10::el9",
    "package" : "multicluster-engine/cluster-curator-controller-rhel9:1787201612"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.11",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59556",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.11::el9",
    "package" : "multicluster-engine/cluster-curator-controller-rhel9:1787238383"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.6",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59579",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.6::el9",
    "package" : "multicluster-engine/cluster-curator-controller-rhel9:1787264185"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.8",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59558",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.8::el9",
    "package" : "multicluster-engine/cluster-curator-controller-rhel9:1787259011"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.9",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59559",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.9::el9",
    "package" : "multicluster-engine/cluster-curator-controller-rhel9:1787201646"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-10059\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-10059" ],
  "name" : "CVE-2026-10059",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}