Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-66792: OpenShift: Unauthorized access to cluster resources
CVE-2026-66792 · published 17 days ago
Summary
A vulnerability in OpenShift allows a user with access to a managed cluster to create a Subscription that gives them elevated permissions. This could lead to unauthorized access and control over cluster resources. To protect your cluster, ensure that user-settable annotations are properly configured and monitored.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | multicluster global hub | All versions |
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
| red hat | red hat openshift container platform 4 | All versions |
| red hat | red hat openshift data foundation 4 | All versions |
Original advisory text
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, cra...
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
References
- https://access.redhat.com/security/cve/CVE-2026-66792 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2507537 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:60386
- https://access.redhat.com/errata/RHSA-2026:60389
- https://access.redhat.com/errata/RHSA-2026:60390
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta