<Vulnerability name="CVE-2026-10059">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-05T08:35:00</PublicDate>
    <Bugzilla id="2483187" url="https://bugzilla.redhat.com/show_bug.cgi?id=2483187" xml:lang="en:us">
cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>9.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-266</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
    </Details>
    <Statement xml:lang="en:us">
This is an Important privilege escalation flaw in Multicluster Engine for Kubernetes. A namespace-scoped tenant administrator can achieve cluster-wide administrative authority by leveraging the ClusterCurator controller's creation of cluster-scoped RBAC for a ServiceAccount within a tenant-controlled namespace. This allows the tenant to mint a token for the controller-created ServiceAccount, granting full control over the cluster.
    </Statement>
    <Acknowledgement xml:lang="en:us">
Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
    </Acknowledgement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_engine:2.10::el9">
        <ProductName>multicluster engine for Kubernetes 2.1</ProductName>
        <ReleaseDate>2026-08-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:59557">RHSA-2026:59557</Advisory>
        <Package name="multicluster-engine/cluster-curator-controller-rhel9">multicluster-engine/cluster-curator-controller-rhel9:1787201612</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_engine:2.11::el9">
        <ProductName>multicluster engine for Kubernetes 2.11</ProductName>
        <ReleaseDate>2026-08-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:59556">RHSA-2026:59556</Advisory>
        <Package name="multicluster-engine/cluster-curator-controller-rhel9">multicluster-engine/cluster-curator-controller-rhel9:1787238383</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_engine:2.6::el9">
        <ProductName>multicluster engine for Kubernetes 2.6</ProductName>
        <ReleaseDate>2026-08-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:59579">RHSA-2026:59579</Advisory>
        <Package name="multicluster-engine/cluster-curator-controller-rhel9">multicluster-engine/cluster-curator-controller-rhel9:1787264185</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_engine:2.8::el9">
        <ProductName>multicluster engine for Kubernetes 2.8</ProductName>
        <ReleaseDate>2026-08-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:59558">RHSA-2026:59558</Advisory>
        <Package name="multicluster-engine/cluster-curator-controller-rhel9">multicluster-engine/cluster-curator-controller-rhel9:1787259011</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:multicluster_engine:2.9::el9">
        <ProductName>multicluster engine for Kubernetes 2.9</ProductName>
        <ReleaseDate>2026-08-25T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:59559">RHSA-2026:59559</Advisory>
        <Package name="multicluster-engine/cluster-curator-controller-rhel9">multicluster-engine/cluster-curator-controller-rhel9:1787201646</Package>
    </AffectedRelease>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-10059
https://nvd.nist.gov/vuln/detail/CVE-2026-10059
    </References>
</Vulnerability>