CVE-2026-66782: Red Hat Advanced Cluster Management For Kubernetes 2

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl get` commands could obtain this token. The possession of this token grants full control over the mesh network, enabling unauthorized management of network resources such as endpoints and secrets.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1788105072 (fixed in 1788105072); before 1788073481 (fixed in 1788073481)

Published 2026-08-18. Last modified 2026-09-03.