Red HatCVE-2026-66781
Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure
Medium5.4CVE-2026-66781 · Published Aug 18, 2026 · updated Sep 3, 2026
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-749
- www.cve.org/CVERecord?id=CVE-2026-66781
- nvd.nist.gov/vuln/detail/CVE-2026-66781
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/errata/RHSA-2026:63016
- access.redhat.com/security/cve/CVE-2026-66781
- bugzilla.redhat.com/show_bug.cgi?id=2507526
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | A flaw was found in the legacy client-initiated account-linking endpoint of... | High7.3 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: secrets in logs | Medium6.5 | No fix yet |
| Aug 18 | Red Hat Multicluster Engine for Kubernetes: information disclosure | High8.7 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management: improper privilege management | Medium5.8 | No fix yet |
| Aug 18 | Red Hat Advanced Cluster Management for Kubernetes 2: code execution | Medium4.4 | No fix yet |
| Aug 18 | reset-credentials flow of the keycloak-services: weak password recovery | Critical9.1 | No fix yet |