Privilege Escalation Vulnerability in Managedcluster-Import-Controller by Red Hat
CVE-2026-66795
9.9CRITICAL
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 17 August 2026
What is CVE-2026-66795?
A security flaw exists within the managedcluster-import-controller, where the logic for auto-approval of Certificate Signing Requests (CSRs) fails to properly validate incoming requests. This oversight allows a privileged service account from a spoke cluster to submit a crafted CSR, thereby potentially leading to privilege escalation. If exploited successfully, an attacker can gain administrative access to the hub cluster, compromising the entire system's security.
Affected Version(s)
multicluster engine for Kubernetes 2.10 1787078272
multicluster engine for Kubernetes 2.11 1787078330
multicluster engine for Kubernetes 2.17 1786577915