SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-66783

MEDIUM · CVSS 4.4 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes allows users with permissions to modify the Submariner Custom Resource to specify an unvalidated image path. This can lead to the execution of arbitrary code with elevated privileges across the entire cluster, including control-plane nodes. Organizations using Kubernetes, especially those with cluster administrators who can modify Submariner resources, should prioritize addressing this high-severity issue to mitigate potential exploitation.

CVE
CVE-2026-66783
Severity
MEDIUM
CVSS
4.4
EPSS
0.28%
Kubernetes

Original NVD Description

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.