CVE-2026-66792: Red Hat Multicluster Global Hub 1.4.9

Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

Affected products

  • Red Hat Multicluster Global Hub 1.4.9: before 1788355439 (fixed in 1788355439); before 1788355599 (fixed in 1788355599); before 1788355417 (fixed in 1788355417)
  • Red Hat Multicluster Global Hub 1.5.8: before 1789515408 (fixed in 1789515408); before 1789515288 (fixed in 1789515288); before 1789478830 (fixed in 1789478830)
  • Red Hat Multicluster Global Hub 1.6.6: before 1790085494 (fixed in 1790085494); before 1790086176 (fixed in 1790086176); before 1790085268 (fixed in 1790085268)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787262214 (fixed in 1787262214); before 1787263584 (fixed in 1787263584)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787259284 (fixed in 1787259284); before 1787263693 (fixed in 1787263693)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1786976940 (fixed in 1786976940); before 1787170830 (fixed in 1787170830)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238598 (fixed in 1787238598); before 1787240030 (fixed in 1787240030)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787242135 (fixed in 1787242135); before 1787242321 (fixed in 1787242321)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787242131 (fixed in 1787242131); before 1787242108 (fixed in 1787242108)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Data Foundation 4

Published 2026-08-17. Last modified 2026-09-29.