MCP Server Kubernetes — CVE-2026-61459 (Critical)
Summary
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.8) in MCP Server Kubernetes. Patch or mitigate promptly.
Operator check
Review CVE-2026-61459 in your asset inventory. Apply patches per vendor guidance and verify Server Kubernetes is not exposed. CVSS score: 9.8.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.