Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.7 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-75569 — mce-operator-bundle: All GitHub Actions pinned by mutable tag, not commit SHA
🎯 Affected products2
- multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/mce-operator-bundle@sha256:fd54c76dcb4e3070c4aeaad12f8cac57caadc69343f35c445259781d99e7e1e4_amd64 as a component of multicluster engine for Kubernetes 2.9
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro Workaround: The vulnerability resides within the build process of `mce-operator-bundle`, specifically concerning the fetching of build logic from a mutable source without integrity verification. As this issue pertains to the build-time integrity of the software, there are no direct runtime configuration or operational controls available for users to mitigate this vulnerability in deployed Red Hat products.