CVE-2026-66786: Red Hat Advanced Cluster Management For Kubernetes 2

Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1788023916 (fixed in 1788023916); before 1788023940 (fixed in 1788023940); before 1788105072 (fixed in 1788105072); before 1788043964 (fixed in 1788043964); before 1788043961 (fixed in 1788043961); before 1788073481 (fixed in 1788073481); …

Published 2026-09-02. Last modified 2026-09-05.