Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-66794: Multicluster Engine for Kubernetes: Unauthenticated Access to Internal Services

CVE-2026-66794 · published 4 days ago
Summary

An attacker can access internal services without logging in. This is a security risk because it could lead to sensitive information being shared or the cluster being compromised. To fix this, update your Multicluster Engine for Kubernetes to the latest version.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat multicluster engine for kubernetes All versions
Original advisory text
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass...
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.
References
Severity
9.3 Critical
CVSS 3.1: 9.3 (MITRE)
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published19 Aug 2026
Updated22 Aug 2026
First seen19 Aug 2026
Sources
CVE-2026-66794 · MITRE
Monitor software like this
Free during beta