Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.6 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-75569 — mce-operator-bundle: All GitHub Actions pinned by mutable tag, not commit SHA
🎯 Affected products2
- multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/mce-operator-bundle@sha256:a2f44bd31e06ee66fd57dd20ec84a19c3ef887e77b189361fb61d59679ebfaeb_amd64 as a component of multicluster engine for Kubernetes 2.10
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#mce-install-intro Workaround: The vulnerability resides within the build process of `mce-operator-bundle`, specifically concerning the fetching of build logic from a mutable source without integrity verification. As this issue pertains to the build-time integrity of the software, there are no direct runtime configuration or operational controls available for users to mitigate this vulnerability in deployed Red Hat products.