CVE-2026-66787
Red Hat · Advanced Cluster Management for Kubernetes
A vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes results from insufficient verification of data authenticity.
Executive summary
A critical vulnerability in the Red Hat Advanced Cluster Management for Kubernetes lighthouse component allows authorized users to bypass data authenticity checks, posing a significant risk of unauthorized operations.
Vulnerability
The lighthouse component fails to properly verify data authenticity (CWE-345), which can be exploited by an attacker with high privileges (PR:H). By manipulating this component, a privileged user can perform unauthorized actions within the cluster management environment.
Business impact
This vulnerability allows a high-privileged user to potentially compromise the integrity of cluster operations. Given the CVSS score of 8.7, the risk of unauthorized configuration changes or lateral movement within the Kubernetes management plane is high. Successful exploitation could lead to total loss of control over the managed clusters and significant operational disruption.
Remediation
Immediate Action: Apply the latest security updates provided by Red Hat for the Advanced Cluster Management for Kubernetes platform as soon as they become available.
Proactive Monitoring: Review administrative audit logs for unusual activity within the lighthouse component or unexpected changes to cluster configuration policies.
Compensating Controls: Implement strict role-based access control (RBAC) to limit the number of users with high-level administrative privileges, thereby reducing the attack surface for this vulnerability.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Security teams should prioritize reviewing the Red Hat security advisory for the specific versions affected by this flaw. Until patches are applied, administrators should audit current high-privileged accounts and restrict access to the lighthouse component to essential personnel only.