Skip to content
Red HatCVE-2026-66781

Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure

Medium5.4CVE-2026-66781 · Published Aug 18, 2026 · updated Sep 3, 2026

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Advanced Cluster Management for Kubernetes 2
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in the legacy client-initiated account-linking endpoint of...
High7.3Aug 18
Red Hat Advanced Cluster Management for Kubernetes 2: secrets in logs
Medium6.5Aug 18
Red Hat Multicluster Engine for Kubernetes: information disclosure
High8.7Aug 18
Red Hat Advanced Cluster Management: improper privilege management
Medium5.8Aug 18
Red Hat Advanced Cluster Management for Kubernetes 2: code execution
Medium4.4Aug 18
reset-credentials flow of the keycloak-services: weak password recovery
Critical9.1Aug 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.