RHSA-2026:59642HighCVSS 7.7

Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.10 security update

Published
August 25, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-75569 — mce-operator-bundle: All GitHub Actions pinned by mutable tag, not commit SHA

🎯 Affected products2

  • multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/mce-operator-bundle@sha256:3f685f251fc5ee1a068dd4359f8d0849636c5c8ee72cf875e4f1bcd600e499bb_amd64 as a component of multicluster engine for Kubernetes 2.8

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro Workaround: The vulnerability resides within the build process of `mce-operator-bundle`, specifically concerning the fetching of build logic from a mutable source without integrity verification. As this issue pertains to the build-time integrity of the software, there are no direct runtime configuration or operational controls available for users to mitigate this vulnerability in deployed Red Hat products.

🔗 References (4)