Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-66795: Managedcluster-import-controller: Malicious CSR Can Grant Hub Cluster Access
CVE-2026-66795 · published 17 days ago
Summary
A security flaw in the managedcluster-import-controller allows a malicious service account on a connected cluster to submit a fake request for a security certificate. If exploited, this could grant the attacker administrative access to the main hub cluster, potentially leading to data theft or system compromise. To mitigate this risk, ensure that security protocols are up-to-date and implement strict access controls for service accounts.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | multicluster engine for kubernetes | All versions |
| red hat | multicluster engine for kubernetes 2.11 | All versions |
| red hat | multicluster engine for kubernetes 2.17 | All versions |
| red hat | multicluster engine for kubernetes 2.10 | All versions |
| red hat | multicluster engine for kubernetes 2.6 | All versions |
| red hat | multicluster engine for kubernetes 2.8 | All versions |
| red hat | multicluster engine for kubernetes 2.9 | All versions |
Original advisory text
Managedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin)
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
References
- https://access.redhat.com/security/cve/CVE-2026-66795
- https://bugzilla.redhat.com/show_bug.cgi?id=2507540
- https://access.redhat.com/errata/RHSA-2026:59556 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59593
- https://access.redhat.com/errata/RHSA-2026:59557 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59558 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59559 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:59579 vendor-advisory x_refsource_REDHAT
Severity
9.9
Critical
CVSS 3.1: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-295Improper Certificate Validation
Timeline
Published17 Aug 2026
Updated2 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta