Description
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
Published: 2026-08-18
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes allows a cluster administrator or any user with permission to modify the Submariner Custom Resource to specify an unvalidated image path. The lack of validation permits an attacker to deploy a malicious image, which results in arbitrary code execution with elevated privileges across all cluster nodes, including control‑plane nodes. This vulnerability is an instance of improper input validation (CWE‑20) and enables full cluster compromise when exploited.

Affected Systems

The Red Hat Advanced Cluster Management for Kubernetes product, version 2, is affected through its submariner‑operator component. The exact version range is not specified, so all current installments of Red Hat Advanced Cluster Management for Kubernetes 2 that include the submariner‑operator should be considered vulnerable until an official fix is released.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity, and while the EPSS score is < 1%, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to have cluster‑admin level permissions or the ability to modify Submariner Custom Resources. Once those privileges are obtained, the attacker can override the image field and achieve code execution with cluster‑wide privileges. Because accessing the image override requires privileged roles, exploitation is limited to compromised or malicious insiders rather than remote attackers with no authentication.

Generated by OpenCVE AI on September 2, 2026 at 07:11 UTC.

Remediation

Vendor Workaround

To mitigate this issue, restrict access to cluster-admin roles and carefully control permissions for users or service accounts that can modify Submariner Custom Resources. Ensure that only trusted and authorized personnel have the ability to patch Submariner CRs, thereby preventing the injection of malicious images.


OpenCVE Recommended Actions

  • Reduce cluster‑admin privileges to only essential personnel.
  • Limit permissions for editing the Submariner Custom Resource to trusted service accounts and users only.
  • Continuously monitor role bindings and Submariner CR changes for unauthorized modifications.

Generated by OpenCVE AI on September 2, 2026 at 07:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.17::el9
References

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
Weaknesses CWE-1357
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 18 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
Title Submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node
First Time appeared Redhat
Redhat acm
Weaknesses CWE-20
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-03T04:41:27.193Z

Reserved: 2026-07-27T17:51:24.885Z

Link: CVE-2026-66783

cve-icon Vulnrichment

Updated: 2026-08-19T15:04:39.637Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T17:17:00.840

Modified: 2026-09-03T13:06:00.620

Link: CVE-2026-66783

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T16:35:00Z

Links: CVE-2026-66783 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:15:04Z

Weaknesses
  • CWE-1357

    Reliance on Insufficiently Trustworthy Component

  • CWE-20

    Improper Input Validation