Remote Code Execution Vulnerability in Submariner by Red Hat
CVE-2026-66786

9.1CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
2 September 2026

What is CVE-2026-66786?

A vulnerability exists in Submariner where the connection configuration in cert-auth mode uses unvalidated free-form strings from the Custom Resource Definition (CRD). This flaw allows a malicious cluster to compromise the system by publishing a CableName containing newlines and ipsec.conf directives. Exploiting this vulnerability can lead to the injection of arbitrary configuration parameters or the execution of commands via leftupdown hooks, potentially resulting in remote code execution with root privileges on the gateway node.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.