RHSA-2026:59638HighCVSS 7.7

Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.7 security update

Published
August 25, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-75569 — mce-operator-bundle: All GitHub Actions pinned by mutable tag, not commit SHA

🎯 Affected products2

  • multicluster engine for Kubernetes 2.9
  • registry.redhat.io/multicluster-engine/mce-operator-bundle@sha256:fd54c76dcb4e3070c4aeaad12f8cac57caadc69343f35c445259781d99e7e1e4_amd64 as a component of multicluster engine for Kubernetes 2.9

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro Workaround: The vulnerability resides within the build process of `mce-operator-bundle`, specifically concerning the fetching of build logic from a mutable source without integrity verification. As this issue pertains to the build-time integrity of the software, there are no direct runtime configuration or operational controls available for users to mitigate this vulnerability in deployed Red Hat products.

🔗 References (4)