SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-66787

MEDIUM · CVSS 5.4 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to create malicious EndpointSlices with attacker-controlled IP addresses. This can lead to redirection of legitimate service traffic, enabling remote attackers to perform transparent Man-in-the-Middle (MITM) attacks on cross-cluster communications, risking unauthorized data access and manipulation. Organizations using Kubernetes, particularly those leveraging Red Hat's Advanced Cluster Management, should prioritize addressing this high-severity issue to safeguard their environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66787
Severity
MEDIUM
CVSS
5.4
EPSS
0.24%
Kubernetes

Original NVD Description

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.