CVE-2026-66795: Red Hat Multicluster Engine For Kubernetes 2.10
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
Affected products
- Red Hat Multicluster Engine For Kubernetes 2.10: before 1787078272 (fixed in 1787078272)
- Red Hat Multicluster Engine For Kubernetes 2.11: before 1787078330 (fixed in 1787078330)
- Red Hat Multicluster Engine For Kubernetes 2.17: before 1786577915 (fixed in 1786577915)
- Red Hat Multicluster Engine For Kubernetes 2.6: before 1787260779 (fixed in 1787260779)
- Red Hat Multicluster Engine For Kubernetes 2.8: before 1787259044 (fixed in 1787259044)
- Red Hat Multicluster Engine For Kubernetes 2.9: before 1787078307 (fixed in 1787078307)
Published 2026-08-17. Last modified 2026-09-29.