Description
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The submariner‑operator component contains a role misconfiguration that grants every joined cluster excessive permissions over the broker namespace. An attacker who compromises a spoke cluster can overwrite the endpoint data of other clusters, redirecting inter‑cluster tunnel traffic and enabling a man‑in‑the‑middle attack across the entire mesh. This flaw directly compromises network confidentiality and integrity for all participants in the cluster network.

Affected Systems

The vulnerability applies to Red Hat Advanced Cluster Management for Kubernetes version 2 through its submariner-operator deployment. No specific patch versions are listed, and the issue is tied to the Role assignment created by the submariner‑k8s‑broker‑cluster component in the broker namespace.

Risk and Exploitability

The reported CVSS score of 6.5 indicates a medium‑severity rating. The EPSS score of 0.00303 (less than 1%) suggests a very low exploitation probability, but the lack of a KEV listing does not diminish the risk; the remediation remains urgent. Attackers would need to compromise a cluster that has joined the broker, which is a plausible scenario in environments using the operator. Because the malicious actor can modify critical network configuration objects, the practical impact is substantial, warranting immediate mitigation.

Generated by OpenCVE AI on September 2, 2026 at 07:11 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Update submariner-operator to a version that removes the over‑privileged submariner-k8s-broker-cluster Role or patches the RBAC configuration; reference Red Hat advisories for the fixed release.
  • If an immediate upgrade is not possible, isolate the broker namespace so that only trusted administrative accounts can bind Roles, and apply least‑privilege RBAC to all spoke clusters.
  • Implement continuous monitoring of broker namespace events and endpoint resource changes to detect unauthorized modifications or attempted MITM activity.

Generated by OpenCVE AI on September 2, 2026 at 07:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.17::el9
References

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace Submariner-operator: broker serviceaccount secret (token + ca) logged in full at trace verbosity
Weaknesses CWE-532
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.16::el9
cpe:/a:redhat:acm:2.17::el9
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 27 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.16::el9
References

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.17::el9
References

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.
Title Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace
First Time appeared Redhat
Redhat acm
Weaknesses CWE-284
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-03T04:41:12.294Z

Reserved: 2026-07-27T17:51:24.885Z

Link: CVE-2026-66780

cve-icon Vulnrichment

Updated: 2026-08-18T18:44:56.550Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T18:19:23.940

Modified: 2026-09-03T13:06:00.197

Link: CVE-2026-66780

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T16:35:00Z

Links: CVE-2026-66780 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:15:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-532

    Insertion of Sensitive Information into Log File