Red HatCVE-2026-66786
Red Hat Advanced Cluster Management for Kubernetes 2: remote code execution
Critical9.1CVE-2026-66786 · Published Sep 2, 2026 · updated Sep 5, 2026
A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-94
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Red Hat rpm: command injection | High7.8 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux 10: command injection | High7.8 | No fix yet |
| Sep 2 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and... | High7.9 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux 10: link following | High7.0 | No fix yet |
| Sep 2 | Red Hat util-linux: race condition | High7.8 | No fix yet |
| Sep 2 | Red Hat Enterprise Linux: open redirect | Medium4.3 | No fix yet |