Excessive Permissions in Submariner-Operator Affecting Red Hat Cluster Management
CVE-2026-66780
9.9CRITICAL
What is CVE-2026-66780?
A vulnerability exists within the submariner-operator component where the submariner-k8s-broker-cluster Role is granted excessive permissions. This flaw potentially allows a compromised cluster to impact network settings by overwriting endpoint information of other clusters. As a result, an attacker can manipulate inter-cluster tunnel traffic, posing risks for Man-in-the-Middle (MITM) attacks throughout the entire cluster mesh.