CVE-2026-66787: Red Hat Advanced Cluster Management For Kubernetes 2.17
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1788023916 (fixed in 1788023916); before 1788023940 (fixed in 1788023940); before 1788105072 (fixed in 1788105072); before 1788073481 (fixed in 1788073481)
Published 2026-08-20. Last modified 2026-09-03.