CVE-2026-10059Critical· 9.1▾ MidnightA flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertent…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73269Critical· 9.9A flaw was found in the cluster-curator-controller component
CVE-2026-73268Critical· 9.9A flaw was found in the cluster-curator-controller component of multicluster engine (MCE)
CVE-2026-15467High· 8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller
CVE-2026-18621High· 7.6A flaw was found in Data Science Pipelines (DSP)
CVE-2025-2843High· 8.8A flaw was found in the Observability Operator
CVE-2026-71468Medium· 5.3A flaw was found in acm-search-v2-api-rhel9