What is CVE-2026-10059?
CVE-2026-10059 is a vulnerability in the ClusterCurator controller of Multicluster Engine for Kubernetes. It allows a tenant administrator with namespace-scoped privileges to mint tokens by creating a specific ClusterCurator, leading to privilege escalation. Affected systems should promptly apply the vendor-provided security patch.
Azərbaycanca: CVE-2026-10059 zəifliyi Multicluster Engine for Kubernetes-in ClusterCurator kontrollerində aşkarlanıb. Bu qüsur, namespace səviyyəsində imtiyazlara malik tenant administratora xüsusi ClusterCurator yaratmaqla token yaratmaq imkanı verir, nəticədə səlahiyyətlərin artırılmasına səbəb olur. Təsirə məruz qalan sistemlərin administratorları dərhal təchizatçı tərəfindən təqdim edilən təhlükəsizlik yamasını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which product is affected by CVE-2026-10059?
CVE-2026-10059 affects the ClusterCurator controller of Multicluster Engine for Kubernetes.
What can an attacker achieve by exploiting CVE-2026-10059?
This flaw allows a tenant administrator with namespace-scoped privileges to achieve privilege escalation by minting tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.