{"api_version":"1","generated_at":"2026-09-05T03:54:41+00:00","cve":"CVE-2026-66786","urls":{"html":"https://cve.report/CVE-2026-66786","api":"https://cve.report/api/cve/CVE-2026-66786.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-66786","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-66786"},"summary":{"title":"Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets","description":"A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-02 18:21:10","updated_at":"2026-09-05 01:16:49"},"problem_types":["CWE-94","CWE-94 Improper Control of Generation of Code ('Code Injection')"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507531","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2507531","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:63016","name":"https://access.redhat.com/errata/RHSA-2026:63016","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-66786","name":"https://access.redhat.com/security/cve/CVE-2026-66786","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-66786","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66786","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788023916 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788023940 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788105072 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788043964 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788043961 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788073481 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","version":"unaffected 1788043970 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-07-27T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-08-21T16:43:00.583Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"If Submariner certificate-based IPsec authentication mode is enabled (`IPSecCertAuthMode: true` in the SubmarinerConfig), administrators can mitigate this flaw by switching to the default pre-shared key (PSK) authentication mode. Set `IPSecCertAuthMode: false` (or remove the field to use its default value) in the SubmarinerConfig CR and redeploy the Submariner gateway pods. PSK mode provides equivalent inter-cluster IPsec tunnel encryption and is not affected by this vulnerability. Note that disabling cert-auth mode means Submariner will no longer integrate with OVN IPsec's certificate infrastructure and will manage its own PSK-based authentication independently.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"66786","cve":"CVE-2026-66786","epss":"0.007370000","percentile":"0.521060000","score_date":"2026-09-04","updated_at":"2026-09-05 00:04:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-66786","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-05T01:01:16.851937Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-05T01:01:30.464Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/lighthouse-agent-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788023916","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/lighthouse-coredns-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788023940","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/subctl-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788105072","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-gateway-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788043964","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-globalnet-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788043961","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-rhel9-operator","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788073481","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:acm:2.17::el9"],"defaultStatus":"affected","packageName":"rhacm2/submariner-route-agent-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2.17","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1788043970","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:acm:2"],"defaultStatus":"affected","packageName":"rhacm2/submariner-addon-rhel9","product":"Red Hat Advanced Cluster Management for Kubernetes 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:acm:2"],"defaultStatus":"affected","packageName":"rhacm2/submariner-operator-bundle","product":"Red Hat Advanced Cluster Management for Kubernetes 2","vendor":"Red Hat"}],"datePublic":"2026-08-21T16:43:00.583Z","descriptions":[{"lang":"en","value":"A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-94","description":"Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-03T04:41:49.247Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2026:63016","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:63016"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-66786"},{"name":"RHBZ#2507531","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507531"}],"timeline":[{"lang":"en","time":"2026-07-27T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-08-21T16:43:00.583Z","value":"Made public."}],"title":"Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets","workarounds":[{"lang":"en","value":"If Submariner certificate-based IPsec authentication mode is enabled (`IPSecCertAuthMode: true` in the SubmarinerConfig), administrators can mitigate this flaw by switching to the default pre-shared key (PSK) authentication mode. Set `IPSecCertAuthMode: false` (or remove the field to use its default value) in the SubmarinerConfig CR and redeploy the Submariner gateway pods. PSK mode provides equivalent inter-cluster IPsec tunnel encryption and is not affected by this vulnerability. Note that disabling cert-auth mode means Submariner will no longer integrate with OVN IPsec's certificate infrastructure and will manage its own PSK-based authentication independently."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-94: Improper Control of Generation of Code ('Code Injection')"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-66786","datePublished":"2026-09-02T17:57:19.436Z","dateReserved":"2026-07-27T17:51:24.885Z","dateUpdated":"2026-09-05T01:01:30.464Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-02 18:21:10","lastModifiedDate":"2026-09-05 01:16:49","problem_types":["CWE-94","CWE-94 Improper Control of Generation of Code ('Code Injection')"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-05T01:01:16.851937Z","id":"CVE-2026-66786","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"66786","Ordinal":"1","Title":"Submariner: submariner: ipsec.conf stanza injection via remote-s","CVE":"CVE-2026-66786","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"66786","Ordinal":"1","NoteData":"A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.","Type":"Description","Title":"Submariner: submariner: ipsec.conf stanza injection via remote-s"}]}}}