Authentication Bypass in Multicluster Engine for Kubernetes by Red Hat
CVE-2026-66794

9.3CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
19 August 2026

What is CVE-2026-66794?

A vulnerability exists in the cluster-proxy-addon component of Red Hat's Multicluster Engine for Kubernetes, allowing unauthenticated attackers to bypass authentication and authorization checks. By manipulating URL path segments, these attackers can proxy requests to arbitrary services across any managed cluster. This oversight enables unauthorized access to internal services that should be protected, thereby increasing the risk of information disclosure and potential compromise of the entire cluster environment.

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.