Arbitrary Code Execution Vulnerability in Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-66783
8.2HIGH
What is CVE-2026-66783?
A vulnerability has been identified within the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes. This flaw allows a cluster administrator or any user with the necessary permissions to modify a Submariner Custom Resource (CR) to set an unchecked image path. This oversight can be exploited by attackers to execute arbitrary code with elevated privileges throughout the cluster, which includes the ability to affect control-plane nodes by deploying malicious images.