Unencrypted IPsec Key Vulnerability in Submariner Operator Affects Red Hat
CVE-2026-66781
6.5MEDIUM
What is CVE-2026-66781?
A significant vulnerability has been identified in the Submariner operator, where the Custom Resource (CR) responsible for configuring network connectivity stores the IPsec pre-shared key in an unencrypted format. This critical key secures communication between Kubernetes clusters, and its exposure could allow unauthorized individuals to access sensitive data transmitted between clusters. If an attacker gains access to this key, they can decrypt the network traffic, potentially leading to the leakage of confidential information and other severe security implications.