Red HatCVE-2026-66795
Red Hat managedcluster-import-controller: privilege escalation
Critical9.9CVE-2026-66795 · Published Aug 17, 2026 · updated Sep 8, 2026
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-295
- www.cve.org/CVERecord?id=CVE-2026-66795
- nvd.nist.gov/vuln/detail/CVE-2026-66795
- access.redhat.com/errata/RHSA-2026:59556
- access.redhat.com/errata/RHSA-2026:59557
- access.redhat.com/errata/RHSA-2026:59558
- access.redhat.com/errata/RHSA-2026:59559
- access.redhat.com/errata/RHSA-2026:59579
- access.redhat.com/errata/RHSA-2026:59593
- access.redhat.com/security/cve/CVE-2026-66795
- bugzilla.redhat.com/show_bug.cgi?id=2507540
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Red Hat Advanced Cluster Management: improper privilege management | High8.8 | No fix yet |
| Aug 17 | Red Hat acm-search-v2-rhel9. This vulnerability: code execution | Critical9.1 | No fix yet |
| Aug 17 | Red Hat multicloud-operators-subscription: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat fakefish: missing authentication | Critical9.3 | No fix yet |
| Aug 17 | Red Hat fakefish: command injection | High7.7 | No fix yet |
| Aug 17 | Red Hat OpenShift AI (RHOAI): remote code execution | High7.9 | No fix yet |