Remote Code Execution Vulnerability in Submariner by Red Hat
CVE-2026-66786
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-66786?
A vulnerability exists in Submariner where the connection configuration in cert-auth mode uses unvalidated free-form strings from the Custom Resource Definition (CRD). This flaw allows a malicious cluster to compromise the system by publishing a CableName containing newlines and ipsec.conf directives. Exploiting this vulnerability can lead to the injection of arbitrary configuration parameters or the execution of commands via leftupdown hooks, potentially resulting in remote code execution with root privileges on the gateway node.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023916
Red Hat Advanced Cluster Management for Kubernetes 2.17 1788023940
Red Hat Advanced Cluster Management for Kubernetes 2.17 1788105072