Description
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.
Published: 2026-08-18
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The submariner-operator component contains a role misconfiguration that grants every joined cluster excessive permissions over the broker namespace. An attacker who compromises a spoke cluster can overwrite the endpoint data of other clusters, redirecting inter‑cluster tunnel traffic and enabling a man‑in‑the‑middle attack across the entire mesh. This flaw directly compromises network confidentiality and integrity for all participants in the cluster network.

Affected Systems

The vulnerability applies to Red Hat Advanced Cluster Management for Kubernetes version 2 through its submariner-operator deployment. No specific patch versions are listed, and the issue is tied to the Role assignment created by the submariner-k8s-broker-cluster component in the broker namespace.

Risk and Exploitability

The reported CVSS score of 9.9 assigns the flaw a high‑severity rating. The EPSS score is not available, but the lack of a KEV listing does not diminish the risk; the remediation remains urgent. Attackers would need to compromise a cluster that has joined the broker, which is a plausible scenario in environments using the operator. Because the malicious actor can modify critical network configuration objects, the practical impact is substantial, warranting immediate mitigation.

Generated by OpenCVE AI on August 18, 2026 at 18:26 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Update submariner-operator to a version that removes the over‑privileged submariner-k8s-broker-cluster Role or patches the RBAC configuration; reference Red Hat advisories for the fixed release.
  • If an immediate upgrade is not possible, isolate the broker namespace so that only trusted administrative accounts can bind Roles, and apply least‑privilege RBAC to all spoke clusters.
  • Implement continuous monitoring of broker namespace events and endpoint resource changes to detect unauthorized modifications or attempted MITM activity.

Generated by OpenCVE AI on August 18, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.
Title Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace
First Time appeared Redhat
Redhat acm
Weaknesses CWE-284
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-18T18:45:01.220Z

Reserved: 2026-07-27T17:51:24.885Z

Link: CVE-2026-66780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T18:19:23.940

Modified: 2026-08-18T18:19:23.940

Link: CVE-2026-66780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T18:30:16Z

Weaknesses