CVE-2026-10059: Multicluster Engine ClusterCurator Token Escalation (CVSS 9.1)
ID: 3dfa94bc-d20d-5a46-a8d8-e9a6b15d0800
STIX ID: report--3dfa94bc-d20d-5a46-a8d8-e9a6b15d0800
Feed Name: CosmicBytez Labs
**Executive summary:** A critical (CVSS 9.1) privilege escalation vulnerability (CVE-2026-10059) in the ClusterCurator controller of Red Hat Multicluster Engine allows a tenant namespace administrator to craft a ClusterCurator resource that causes the controller to mint cluster-scoped service account tokens, enabling namespace escape, cross-cluster lateral movement, and secret exfiltration; Red Hat has published a patch and the advisory includes detection indicators, mitigation workarounds, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
