Red HatCVE-2026-66794
Red Hat: authentication bypass
Critical9.3CVE-2026-66794 · Published Aug 19, 2026 · updated Sep 8, 2026
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-918
- www.cve.org/CVERecord?id=CVE-2026-66794
- nvd.nist.gov/vuln/detail/CVE-2026-66794
- access.redhat.com/errata/RHSA-2026:59556
- access.redhat.com/errata/RHSA-2026:59557
- access.redhat.com/errata/RHSA-2026:59558
- access.redhat.com/errata/RHSA-2026:59559
- access.redhat.com/errata/RHSA-2026:59579
- access.redhat.com/errata/RHSA-2026:59593
- access.redhat.com/security/cve/CVE-2026-66794
- bugzilla.redhat.com/show_bug.cgi?id=2507539
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Red Hat search-indexer. This vulnerability: protection mechanism failure | Medium6.8 | No fix yet |
| Aug 19 | Red Hat acm-operator-bundle. The build process: untrusted functionality included | High8.0 | No fix yet |
| Aug 19 | Red Hat mce-operator-bundle. The build process fetches: remote code execution | High7.7 | No fix yet |
| Aug 19 | Red Hat Advanced Cluster Management for Kubernetes 2: improper access control | Critical9.9 | No fix yet |
| Aug 19 | Red Hat volsync-addon-controller. This vulnerability: code injection | Medium6.2 | No fix yet |
| Aug 19 | Red Hat search-v2-operator. This vulnerability: privilege escalation | Critical9.1 | No fix yet |