CVE-2026-61459
A security flaw in MCP Server Kubernetes allows attackers to bypass security checks by using special characters in specific parameters. This allows them to redirect commands to a malicious server.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running suyogs mcp-server-kubernetes versions prior to 3.9.0.
Real-world impact
An attacker can trick the system into sending sensitive credentials, such as a bearer token, to a server they control. This can lead to a complete takeover of the entire Kubernetes cluster.
Why this severity
The critical score is due to the fact that an attacker can exploit this remotely without any user interaction or special privileges, potentially leading to total system compromise.
What to do about it
- 01Upgrade MCP Server Kubernetes to version 3.9.0 or later.
NVD-referenced vendor advisory
Timeline
- Jul 10, 2026 · 24d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 17, 2026 · 17d agoAdvisory updatedThe NVD record was last revised.
- Jul 19, 2026 · 16d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/Flux159/mcp-server-kubernet…patch
- github.com/Flux159/mcp-server-kubernet…issue trackingexploitmitigation
- github.com/Flux159/mcp-server-kubernet…issue trackingpatch
- github.com/Flux159/mcp-server-kubernet…release notes
- vulncheck.com/advisories/mcp-server-kuber…third party advisory