Fetching from the wire…
Security2026-06-12 · source-backed
Disclosed June 11, this flaw lets any client circumvent intended restrictions on Kubernetes operations, which makes environment-variable-based access controls cosmetic. Adversa AI has the details. If you're running this MCP server to give agents cluster access, upgrade to 3.6.0 now and stop treating env-var gating as authorization. This is the second time this year I've seen "we gated it with an env var" turn out to mean "we didn't gate it." Env vars are configuration, not a security boundary. Agents reaching production infrastructure need real RBAC behind them.
Each link below shares sources, entities, or timing with this story.
Adversa AI criticizes MCP / Shared entities / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Adversa AI criticizes MCP); both cover Adversa AI, CVSS, MCP; reported by the same outlet (adversa.ai).
Adversa AI criticizes MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVSS, MCP; overlapping topics (client, cvss).
Adversa AI criticizes MCP / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Adversa AI criticizes MCP); both cover Adversa AI, CVE, MCP; reported by the same outlet (adversa.ai).
Adversa AI criticizes MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVSS, MCP; overlapping topics (configuration, cvss).
Adversa AI criticizes MCP / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVSS, MCP; earlier CVE coverage from 2026-03-23.
Adversa AI criticizes MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVSS, MCP; overlapping topics (agent, cvss).
Adversa AI criticizes MCP / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, MCP; overlapping topics (access, agent).
Adversa AI criticizes Anthropic / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Adversa AI criticizes Anthropic); both cover CVE, Kubernetes; overlapping topics (access, agent, control).