CVE-2026-46519Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (tools/list) but not at the execution layer (tools/call). Any client that knows a tool name can invoke it directly regardless of the configured restriction mode. The access control was effectively cosmetic. This issue has been patched in version 3.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-05-18); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-06-13: 1Mentions · 2026-06-15: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-15: 105-1805-1905-2106-1306-15
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-05-191
Disclosure1
2026-05-211
Disclosure1
2026-06-131
General1
2026-06-151
General1
Full discourse5 posts
  • Ax Sharma@Ax_Sharma
    Disclosure

    The read-only mode in mcp-server-kubernetes (20,000+ weekly npm downloads) ...doesn't actually restrict anything. Neither do the other two access control modes. CVE-2026-46519, CVSS 8.8 🧵 https://t.co/M6ai5LRBJv

    Post summary

    The tweet indicates that access control modes in mcp-server-kubernetes do not enforce restrictions, referencing CVE‑2026‑46519 with a CVSS score of 8.8.

    393421963.2K
    5.3K followersView on X
  • PolicyLayer@PolicyLayer
    General

    CVE-2026-46519 in mcp-server-kubernetes is worth understanding. CVSS 8.8. The access controls were real — they just didn't apply at the right layer.

    Post summary

    The tweet highlights CVE‑2026‑46519, noting its high CVSS score and the issue with access control application, but lacks specifics on PoC, exploit code, patch, or active exploitation.

    1000028
    62 followersView on X
  • Manifold Security@Manifold_ai_sec
    Disclosure

    CVE-2026-46519 (CVSS 8.8). Our research team found a high-severity access control bypass in mcp-server-kubernetes. 20K+ weekly npm downloads. 🧵 https://t.co/ADcCFw4JBu

    Post summary

    Researchers have disclosed CVE‑2026‑46519, a high‑severity access control bypass in mcp‑server‑kubernetes, rated CVSS 8.8, with no patch or exploit details provided.

    1000078
    7 followersView on X
  • Itknowledgebases@IT_KBs
    General

    CVE-2026-46519: Kubernetes MCP Security Flaw https://itknowledgebases.com/cve-2026-46519-kubernetes-mcp-security-flaw/

    Post summary

    The excerpt simply cites a blog post about CVE‑2026‑46519, a Kubernetes MCP security flaw, without providing deeper technical, exploit, or mitigation information.

    0000021
    2 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 mcp-server-#kubernetes, Tool Access Control Bypass, #CVE-2026-46519 (Critical) https://dailycve.com/mcp-server-kubernetes-tool-access-control-bypass-cve-2026-46519-critical/

    Post summary

    The text announces a new critical CVE‑2026‑46519 affecting mcp‑server for Kubernetes, describing it as a tool access control bypass.

    0000055
    207 followersView on X

Explore more