CVE-2026-66780
9.9Red Hat · Advanced Cluster Management for Kubernetes
A flaw in the submariner-operator component allows a compromised cluster to perform MITM attacks across a cluster mesh by overwriting endpoint information due to excessive permissions.
Executive summary
A critical access control vulnerability in Red Hat Advanced Cluster Management for Kubernetes allows an authenticated attacker to compromise inter-cluster traffic security.
Vulnerability
The vulnerability exists in the submariner-operator component, specifically within the submariner-k8s-broker-cluster Role. This flaw permits an attacker with low-level authenticated access to a joined cluster to manipulate network configurations and redirect inter-cluster tunnel traffic.
Business impact
The exploitation of this vulnerability carries a high risk to business operations, as it facilitates unauthorized interception of sensitive data transferred between clusters. With a CVSS score of 9.9, the potential for a complete Man-in-the-Middle attack across the entire cluster mesh could lead to total compromise of confidentiality, integrity, and availability within the affected Kubernetes environment.
Remediation
Immediate Action: Update Red Hat Advanced Cluster Management for Kubernetes 2 to the latest version as provided by the vendor.
Proactive Monitoring: Monitor inter-cluster network traffic for unusual redirection patterns and review Kubernetes access logs for unauthorized modifications to endpoint configurations.
Compensating Controls: Implement strict network policies and service mesh security controls to limit the blast radius of a potentially compromised cluster.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the critical nature of this flaw and its potential to disrupt the security of an entire Kubernetes mesh, organizations should prioritize patching immediately. Ensure that the latest updates are applied to the submariner-operator component to remediate the excessive permissioning issue and prevent potential traffic interception.