{"api_version":"1","generated_at":"2026-08-28T04:18:49+00:00","cve":"CVE-2026-66780","urls":{"html":"https://cve.report/CVE-2026-66780","api":"https://cve.report/api/cve/CVE-2026-66780.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-66780","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-66780"},"summary":{"title":"Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace","description":"A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-08-18 18:19:23","updated_at":"2026-08-27 04:16:45"},"problem_types":["CWE-284","CWE-284 Improper Access Control"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507524","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2507524","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-66780","name":"https://access.redhat.com/security/cve/CVE-2026-66780","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60389","name":"https://access.redhat.com/errata/RHSA-2026:60389","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60388","name":"https://access.redhat.com/errata/RHSA-2026:60388","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60387","name":"https://access.redhat.com/errata/RHSA-2026:60387","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60390","name":"https://access.redhat.com/errata/RHSA-2026:60390","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60391","name":"https://access.redhat.com/errata/RHSA-2026:60391","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:60386","name":"https://access.redhat.com/errata/RHSA-2026:60386","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-66780","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66780","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.11","version":"unaffected 1787689013 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.13","version":"unaffected 1787365971 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.14","version":"unaffected 1787362756 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.15","version":"unaffected 1787362733 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.16","version":"unaffected 1787362694 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1787362658 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-07-27T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-08-18T16:35:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"66780","cve":"CVE-2026-66780","epss":"0.003030000","percentile":"0.223990000","score_date":"2026-08-27","updated_at":"2026-08-28 00:03:40"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-66780","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-18T18:44:52.061095Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-18T18:45:01.220Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.11::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.11","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787689013","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.13::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.13","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787365971","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.14::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.14","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787362756","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.15::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.15","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787362733","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.16::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.16","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787362694","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1787362658","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:acm:2"],"defaultStatus":"affected","packageName":"rhacm2/subctl-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:acm:2"],"defaultStatus":"affected","packageName":"rhacm2/submariner-operator-bundle","product":"Red Hat Advanced Cluster Management for Kubernetes 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:acm:2"],"defaultStatus":"affected","packageName":"rhacm2/submariner-rhel9-operator","product":"Red Hat Advanced Cluster Management for Kubernetes 2","vendor":"Red Hat"}],"datePublic":"2026-08-18T16:35:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-27T02:15:36.990Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2026:60386","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60386"},{"name":"RHSA-2026:60387","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60387"},{"name":"RHSA-2026:60388","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60388"},{"name":"RHSA-2026:60389","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60389"},{"name":"RHSA-2026:60390","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60390"},{"name":"RHSA-2026:60391","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:60391"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-66780"},{"name":"RHBZ#2507524","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507524"}],"timeline":[{"lang":"en","time":"2026-07-27T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-08-18T16:35:00.000Z","value":"Made public."}],"title":"Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-284: Improper Access Control"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-66780","datePublished":"2026-08-18T17:32:00.879Z","dateReserved":"2026-07-27T17:51:24.885Z","dateUpdated":"2026-08-27T02:15:36.990Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-18 18:19:23","lastModifiedDate":"2026-08-27 04:16:45","problem_types":["CWE-284","CWE-284 Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-18T18:44:52.061095Z","id":"CVE-2026-66780","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"66780","Ordinal":"1","Title":"Submariner-operator: submariner-operator: flat broker trust mode","CVE":"CVE-2026-66780","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"66780","Ordinal":"1","NoteData":"A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.","Type":"Description","Title":"Submariner-operator: submariner-operator: flat broker trust mode"}]}}}