CVE-2026-47250: mcp-server-kubernetes kubectl_generic allows token exfiltration via log prompt injection
Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passed user-supplied flags to kubectl without an allowlist, letting an attacker plant injected instructions in application logs so that an operator's AI agent redirects kubectl to an attacker-controlled server and leaks the operator's bearer token. The captured token could be replayed against the real Kubernetes API, granting the attacker the operator's full RBAC permissions; it was patched in version 3.7.0.
Disclosed 11 June 2026 · Record updated 13 September 2026
Impact
Privilege escalation within Kubernetes environments: an attacker with limited access could capture a privileged operator's Authorization bearer token and replay it against the Kubernetes API server to gain the operator's full RBAC permissions.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47250
