CVE-2026-61459 CRITICAL

CVE-2026-61459: MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools

Vendor Flux159
Product mcp-server-kubernetes
Weakness CWE-88
Published July 10, 2026
Last update July 13, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.

Key dates

02Disclosure timeline

July 10, 2026 CVE published
July 13, 2026 Record updated