PT-2026-77227 · Red Hat · Red Hat Advanced Cluster Management For Kubernetes 2+1

CVE-2026-66783

·

Published

2026-08-18

·

Updated

2026-09-03

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Advanced Cluster Management for Kubernetes (affected versions not specified)
Description A flaw in the submariner-operator component allows a cluster administrator or any user with permissions to modify the Submariner Custom Resource (CR) to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66783

Affected Products

Red Hat Advanced Cluster Management For Kubernetes 2
Red Hat Advanced Cluster Management For Kubernetes 2.17