Excessive Permissions in Submariner-Operator Affecting Red Hat Cluster Management
CVE-2026-66780
6.5MEDIUM
Key Information:
What is CVE-2026-66780?
A vulnerability exists within the submariner-operator component where the submariner-k8s-broker-cluster Role is granted excessive permissions. This flaw potentially allows a compromised cluster to impact network settings by overwriting endpoint information of other clusters. As a result, an attacker can manipulate inter-cluster tunnel traffic, posing risks for Man-in-the-Middle (MITM) attacks throughout the entire cluster mesh.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.11 1789135606
Red Hat Advanced Cluster Management for Kubernetes 2.13 1789131397
Red Hat Advanced Cluster Management for Kubernetes 2.14 1789136328