CVE-2026-66878: Red Hat Advanced Cluster Management For Kubernetes 2.11

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263584 (fixed in 1787263584)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787263693 (fixed in 1787263693)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787170830 (fixed in 1787170830)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787240030 (fixed in 1787240030)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787242321 (fixed in 1787242321)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787242108 (fixed in 1787242108)

Published 2026-08-12. Last modified 2026-08-27.