Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-66795: Managedcluster-import-controller: Malicious CSR Can Grant Hub Cluster Access

CVE-2026-66795 · published 17 days ago
Summary

A security flaw in the managedcluster-import-controller allows a malicious service account on a connected cluster to submit a fake request for a security certificate. If exploited, this could grant the attacker administrative access to the main hub cluster, potentially leading to data theft or system compromise. To mitigate this risk, ensure that security protocols are up-to-date and implement strict access controls for service accounts.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat multicluster engine for kubernetes All versions
red hat multicluster engine for kubernetes 2.11 All versions
red hat multicluster engine for kubernetes 2.17 All versions
red hat multicluster engine for kubernetes 2.10 All versions
red hat multicluster engine for kubernetes 2.6 All versions
red hat multicluster engine for kubernetes 2.8 All versions
red hat multicluster engine for kubernetes 2.9 All versions
Original advisory text
Managedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
Severity
9.9 Critical
CVSS 3.1: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-295Improper Certificate Validation
Timeline
Published17 Aug 2026
Updated2 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-66795 · MITRE
Monitor software like this
Free during beta