Skip to content
Red HatCVE-2026-66787

Red Hat lighthouse: information disclosure

Medium5.4CVE-2026-66787 · Published Aug 20, 2026 · updated Sep 3, 2026

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat multicloud-operators-subscription: information disclosure
High7.7Aug 20
A flaw was found in the multicloud-operators-subscription component
Critical9.9Aug 20
Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure
Low2.5Aug 20
Red Hat Lighthouse. A remote attacker: privilege escalation
Low3.7Aug 20
A flaw was found in Kata Containers
High8.1Aug 20
A flaw was found in WildFly Elytron
High7.4Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.