MCP Server Kubernetes — CVE-2026-61459 (Critical)

Date Jul 10, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product MCP · Server Kubernetes
CVE CVE-2026-61459
Critical vendor advisory CVE-2026-61459

Summary

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.8) in MCP Server Kubernetes. Patch or mitigate promptly.

Operator check

Review CVE-2026-61459 in your asset inventory. Apply patches per vendor guidance and verify Server Kubernetes is not exposed. CVSS score: 9.8.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.