<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:41:22 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-10059 — Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-10059</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat multicluster engine for Kubernetes 2.1, Red Hat multicluster engine for Kubernetes 2.11, Red Hat multicluster engine for Kubernetes 2.6, Red Hat multicluster engine for Kubernetes 2.8, Red Hat multicluster engine for Kubernetes 2.9&lt;/p&gt;
&lt;p&gt;A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Red Hat multicluster engine for Kubernetes 2.1, Red Hat multicluster engine for Kubernetes 2.11, Red Hat multicluster engine for Kubernetes 2.6, Red Hat multicluster engine for Kubernetes 2.8, Red Hat multicluster engine for Kubernetes 2.9&lt;/p&gt;
&lt;p&gt;A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-10059</guid>
    </item>
  </channel>
</rss>
