SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66788

LOW · CVSS 3.7 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical vulnerability exists in Lighthouse that allows remote attackers to exploit compromised spoke clusters by manipulating labels or annotations on broker objects. This enables unauthorized injection of EndpointSlices and ServiceImports into any namespace, including sensitive system namespaces like kube-system, potentially leading to privilege escalation and severe system compromise. Organizations using Lighthouse should prioritize immediate remediation to protect their clusters from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66788
Severity
LOW
CVSS
3.7
EPSS
0.28%

Original NVD Description

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.