Red Hat Security Advisory: multicluster engine for Kubernetes v2.11.6 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-75569 — mce-operator-bundle: All GitHub Actions pinned by mutable tag, not commit SHA
🎯 Affected products2
- multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/mce-operator-bundle@sha256:8a49127018dce064332524e43158d247ddcb8d6cd4969fbd21d0febcba9ce6c6_amd64 as a component of multicluster engine for Kubernetes 2.11
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/clusters/cluster_mce_overview#mce-install-intro Workaround: The vulnerability resides within the build process of `mce-operator-bundle`, specifically concerning the fetching of build logic from a mutable source without integrity verification. As this issue pertains to the build-time integrity of the software, there are no direct runtime configuration or operational controls available for users to mitigate this vulnerability in deployed Red Hat products.