CVE-2026-61459Suyogs · Mcp-server-kubernetes
Vulnerability data via NVD (ingested)
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the --server flag to redirect kubectl commands to an attacker-controlled API server, causing the operator's bearer token to be transmitted externally and enabling full cluster compromise.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-61459product:"Suyogs Mcp-server-kubernetes"http.html:"Mcp-server-kubernetes"More intel sources (5)
vuln:CVE-2026-61459vulnerabilities.cve_id: CVE-2026-61459CVE-2026-61459CVE-2026-61459"CVE-2026-61459" exploit -site:nvd.nist.gov