Privilege Escalation Vulnerability in Managedcluster-Import-Controller by Red Hat
CVE-2026-66795

9.9CRITICAL

What is CVE-2026-66795?

A security flaw exists within the managedcluster-import-controller, where the logic for auto-approval of Certificate Signing Requests (CSRs) fails to properly validate incoming requests. This oversight allows a privileged service account from a spoke cluster to submit a crafted CSR, thereby potentially leading to privilege escalation. If exploited successfully, an attacker can gain administrative access to the hub cluster, compromising the entire system's security.

Affected Version(s)

multicluster engine for Kubernetes 2.10 1787078272

multicluster engine for Kubernetes 2.11 1787078330

multicluster engine for Kubernetes 2.17 1786577915

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.