CVE-2026-66793
Red Hat · Advanced Cluster Management for Kubernetes 2
A flaw in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes allows for improper input validation.
Executive summary
Red Hat Advanced Cluster Management for Kubernetes contains an improper input validation vulnerability that could allow authenticated users to compromise system integrity.
Vulnerability
The governance-policy-addon-controller component fails to properly validate inputs, which, when exploited by an authenticated user, can lead to significant security impacts.
Business impact
With a CVSS score of 8.8, this vulnerability presents a high risk to the environment. Successful exploitation could lead to unauthorized access, data compromise, or disruption of cluster management services, significantly impacting business operations.
Remediation
Immediate Action: Consult the Red Hat security advisory and apply the provided security patches or configuration updates for the governance-policy-addon-controller.
Proactive Monitoring: Review cluster management logs for unusual policy changes or unexpected controller behavior.
Compensating Controls: Apply strict Role-Based Access Control (RBAC) to limit the number of users who can interact with the governance-policy-addon-controller.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Security teams should treat this high-severity vulnerability with urgency. Review the official Red Hat security documentation to identify the specific patched versions and ensure all clusters are brought into compliance to prevent potential exploitation.