CVE-2026-66787
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS probability
- 0.24%
- CWE
- CWE-345, CWE-489
- Published
- 2026-08-20
- Last modified
- 2026-09-03
Affected products
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
- Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17
Weakness type
Related vulnerabilities
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-73316 — XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
- CVE-2026-85008 — undici vulnerable to caching and replay of unsafe HTTP method responses
- CVE-2026-85621 — LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
- CVE-2026-85435 — MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
- CVE-2026-85434 — MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping
- CVE-2026-85431 — MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection
- CVE-2026-85430 — MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing