Unencrypted IPsec Key Vulnerability in Submariner Operator Affects Red Hat
CVE-2026-66781

5.4MEDIUM

What is CVE-2026-66781?

A significant vulnerability has been identified in the Submariner operator, where the Custom Resource (CR) responsible for configuring network connectivity stores the IPsec pre-shared key in an unencrypted format. This critical key secures communication between Kubernetes clusters, and its exposure could allow unauthorized individuals to access sensitive data transmitted between clusters. If an attacker gains access to this key, they can decrypt the network traffic, potentially leading to the leakage of confidential information and other severe security implications.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787689013

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787365971

Red Hat Advanced Cluster Management for Kubernetes 2.14 1787362756

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.