CVE-2026-46519: Access-Control Bypass in mcp-server-kubernetes (CVSS 8.8), Patched in 3.6.0
Adversa AI·high signal
Disclosed June 11, CVE-2026-46519 is a high-severity flaw in mcp-server-kubernetes that lets any client circumvent intended restrictions on Kubernetes operations, rendering environment-variable-based access controls cosmetic. It is fixed in version 3.6.0 — anyone running this MCP server to give agents cluster access should upgrade immediately and stop relying on env-var gating for authorization.