Critical Flaw in ClusterCurator for Kubernetes Detected
A critical vulnerability, reportedly affecting the ClusterCurator component for Kubernetes, appears to allow tenant administrators with namespace-scoped privileges to gain full control over the cluster.
What happened
An early warning has been issued regarding a critical vulnerability, tracked as CVE-2026-10059, in the ClusterCurator component for Kubernetes. This flaw, with a CVSS score of 9.1, reportedly allows a tenant administrator with namespace-scoped privileges to create a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority, leading to privilege escalation and full control over the cluster. The vulnerability is under investigation, and it is recommended to upgrade to the latest version of ClusterCurator and review tenant privileges to prevent potential exploitation. For more detailed information, consult the primary sources.
How 0Day mitigates this
clustercurator is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.