Arbitrary Code Execution Vulnerability in Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-66783

4.4MEDIUM

What is CVE-2026-66783?

A vulnerability has been identified within the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes. This flaw allows a cluster administrator or any user with the necessary permissions to modify a Submariner Custom Resource (CR) to set an unchecked image path. This oversight can be exploited by attackers to execute arbitrary code with elevated privileges throughout the cluster, which includes the ability to affect control-plane nodes by deploying malicious images.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072

Red Hat Advanced Cluster Management for Kubernetes 2.17 1788073481

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.