Excessive Permissions in Submariner-Operator Affecting Red Hat Cluster Management
CVE-2026-66780

6.5MEDIUM

What is CVE-2026-66780?

A vulnerability exists within the submariner-operator component where the submariner-k8s-broker-cluster Role is granted excessive permissions. This flaw potentially allows a compromised cluster to impact network settings by overwriting endpoint information of other clusters. As a result, an attacker can manipulate inter-cluster tunnel traffic, posing risks for Man-in-the-Middle (MITM) attacks throughout the entire cluster mesh.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1789135606

Red Hat Advanced Cluster Management for Kubernetes 2.13 1789131397

Red Hat Advanced Cluster Management for Kubernetes 2.14 1789136328

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.