CVE-2026-66788: Red Hat Advanced Cluster Management For Kubernetes 2.17

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1788023916 (fixed in 1788023916); before 1788023940 (fixed in 1788023940); before 1788105072 (fixed in 1788105072); before 1788073481 (fixed in 1788073481)

Published 2026-08-20. Last modified 2026-09-03.