Arbitrary Code Execution Vulnerability in Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-66783

8.2HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 August 2026

What is CVE-2026-66783?

A vulnerability has been identified within the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes. This flaw allows a cluster administrator or any user with the necessary permissions to modify a Submariner Custom Resource (CR) to set an unchecked image path. This oversight can be exploited by attackers to execute arbitrary code with elevated privileges throughout the cluster, which includes the ability to affect control-plane nodes by deploying malicious images.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.