← العودة للجدول
CVE-2026-46519
CVE-2026-46519 — mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster
📅 2026-06-11
🟠 High 🔥 No NVD Wiper Containers CVSS 8.8

📋 الوصف الكامل

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (too

💻 الأنظمة المتأثرة

Kubernetes

⚠️ نوع التهديد

Wiper

🔗 CVE ID

CVE-2026-46519

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.6.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←