SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66793

HIGH · CVSS 8.8 EPSS 0.76% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the governance-policy-addon-controller of Red Hat Advanced Cluster Management for Kubernetes allows users with permission to annotate the ManagedClusterAddOn resource to override the governance-policy container image. This flaw can be exploited to execute arbitrary code with cluster-admin privileges, posing a significant risk of privilege escalation. Organizations using this Kubernetes management solution should prioritize patching to mitigate potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66793
Severity
HIGH
CVSS
8.8
EPSS
0.76%
Kubernetes

Original NVD Description

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.