Unencrypted IPsec Key Vulnerability in Submariner Operator Affects Red Hat
CVE-2026-66781

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 August 2026

What is CVE-2026-66781?

A significant vulnerability has been identified in the Submariner operator, where the Custom Resource (CR) responsible for configuring network connectivity stores the IPsec pre-shared key in an unencrypted format. This critical key secures communication between Kubernetes clusters, and its exposure could allow unauthorized individuals to access sensitive data transmitted between clusters. If an attacker gains access to this key, they can decrypt the network traffic, potentially leading to the leakage of confidential information and other severe security implications.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.