Network Traffic Redirection Vulnerability in Submariner by Red Hat
CVE-2026-66785

2.5LOW

What is CVE-2026-66785?

A vulnerability exists in Submariner that enables a malicious cluster to misdirect network traffic from connected peer clusters. By incorrectly validating network subnets, an attacker can create a fabricated network endpoint that declares arbitrary network ranges. As a result, any traffic directed to these ranges is rerouted through the attacker's tunnel, which could lead to potential information leaks or disruption of network services.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023916

Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023940

Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.