CVE-2026-46519: Why Your Kubernetes MCP Server May Be Open to Attack
Blog post from NeuralTrust
Security researchers have identified a critical vulnerability, CVE-2026-46519, within the mcp-server-kubernetes project, which poses a significant threat due to its high CVSS score of 8.8 and widespread use, with over 20,000 weekly downloads on npm. The vulnerability allows AI agents to bypass access controls intended to limit actions to "read-only" or "non-destructive" operations, thus enabling them to execute unauthorized commands beyond their scope. This issue arises from a disconnect between how the server advertises its capabilities and how it executes them, with controls enforced only at the discovery layer but not at the execution layer, making the security boundaries purely cosmetic. The exploit's impact is exacerbated by the permissions granted to the Kubernetes Service Account, particularly in environments where the MCP server operates with cluster-admin privileges, potentially allowing attackers full control over the cluster. The vulnerability underscores the importance of adhering to the Principle of Least Privilege and updating to version 3.6.0 or later, which rectifies the issue by enforcing restrictions at the execution layer. Additionally, implementing a defense-in-depth strategy, including network isolation, robust authentication, and granular RBAC, is essential to safeguard Kubernetes clusters while leveraging AI capabilities.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 12 | 2,019 | 384 | 116 | -16% |
| MCP | 12 | 7,755 | 814 | 203 | -3% |
| AI Agents | 5 | 5,657 | 1,451 | 270 | -3% |
| Secrets Management | 1 | 2,324 | 403 | 114 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.