An agent server is a credential with a chat window attached. Teams spent years shrinking service account permissions, then wired agent tooling into production ahead of any policy for it. One dash was enough to prove the cost.
- CVE-2026-61459, CVSS 9.3, in mcp-server-kubernetes before 3.9.0.
- A parameter starting with a dash slipped past the flag check meant to block dangerous options.
- Attackers injected the server flag and pointed kubectl at their own API server.
- The operator’s bearer token leaked, giving full cluster compromise.
- Fixed in 3.9.0. The advisory landed in July 2026.
The lesson outlasts the patch. Agent tools are credentials, so scope them like it.
Read the full analysis at One Leading Dash Was Enough to Hand Over a Kubernetes Cluster
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
