Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace
Summary
| CVE | CVE-2026-66780 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-18 18:19:23 UTC |
| Updated | 2026-08-27 04:16:45 UTC |
| Description | A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh. |
Risk And Classification
Primary CVSS: v3.1 9.9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.003030000 probability, percentile 0.223990000 (date 2026-08-27)
Problem Types: CWE-284 | CWE-284 Improper Access Control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.11 | unaffected 1787689013 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.13 | unaffected 1787365971 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.14 | unaffected 1787362756 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.15 | unaffected 1787362733 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.16 | unaffected 1787362694 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2.17 | unaffected 1787362658 * rpm | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-66780 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60389 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60388 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60387 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60390 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60391 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60386 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-07-27T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2026-08-18T16:35:00.000Z | Made public. |
Workarounds
CNA: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
There are currently no legacy QID mappings associated with this CVE.