Authentication Bypass in Multicluster Engine for Kubernetes by Red Hat
CVE-2026-66794

9.3CRITICAL

What is CVE-2026-66794?

A vulnerability exists in the cluster-proxy-addon component of Red Hat's Multicluster Engine for Kubernetes, allowing unauthenticated attackers to bypass authentication and authorization checks. By manipulating URL path segments, these attackers can proxy requests to arbitrary services across any managed cluster. This oversight enables unauthorized access to internal services that should be protected, thereby increasing the risk of information disclosure and potential compromise of the entire cluster environment.

Affected Version(s)

multicluster engine for Kubernetes 2.10 1787173361

multicluster engine for Kubernetes 2.11 1787276784

multicluster engine for Kubernetes 2.17 1786983349

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.