{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asubmarinersubmariner/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:submariner:submariner:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-66786"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Submariner (cert-auth mode)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","kubernetes","cve","cloud"],"_cs_type":"advisory","_cs_vendors":["Submariner"],"content_html":"\u003cp\u003eCVE-2026-66786 is a critical vulnerability identified in Submariner when operating in cert-auth mode. The flaw stems from insufficient validation of user-supplied input within Custom Resource Definitions (CRDs). Specifically, the connection configuration is constructed using free-form strings from the CableName parameter. An attacker with the ability to modify or publish a CRD can inject newline characters alongside malicious ipsec.conf directives.\u003c/p\u003e\n\u003cp\u003eBy manipulating these directives, an attacker can influence the execution of leftupdown hooks within the IPsec configuration. Because these hooks are executed in the context of the gateway node, this vulnerability facilitates remote code execution with root privileges. This poses a significant risk to the integrity and confidentiality of multi-cluster Kubernetes environments utilizing Submariner for cross-cluster connectivity. Defenders should prioritize restricting access to CRD creation and update operations and monitor for anomalous configurations within Submariner resources.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains write access to the Kubernetes API server or manages a cluster federated via Submariner.\u003c/li\u003e\n\u003cli\u003eAttacker initiates the creation or modification of a Submariner CRD object.\u003c/li\u003e\n\u003cli\u003eAttacker injects a payload into the CableName field containing newline characters and crafted ipsec.conf directives.\u003c/li\u003e\n\u003cli\u003eThe Submariner controller processes the malicious CRD, appending the injection strings to the local IPsec configuration files.\u003c/li\u003e\n\u003cli\u003eThe underlying IPsec service reloads, processing the injected configuration directives.\u003c/li\u003e\n\u003cli\u003eThe system invokes the configured leftupdown hooks as defined by the attacker's injected parameters.\u003c/li\u003e\n\u003cli\u003eThe gateway node executes the arbitrary commands defined in the hook with root-level privileges.\u003c/li\u003e\n\u003cli\u003eAttacker achieves persistent command execution and potential lateral movement across the connected clusters.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66786 results in full system compromise of the gateway node with root privileges. In a multi-cluster deployment, this allows an attacker to bridge the security boundary between clusters, leading to potential data exfiltration, service disruption, and total control over the interconnected network fabric. No victim counts or sector-specific data are currently available, but any organization using Submariner in cert-auth mode is considered at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict RBAC permissions for creating or updating Submariner Custom Resource Definitions to trusted administrative service accounts.\u003c/li\u003e\n\u003cli\u003eAudit existing Submariner CRDs for non-standard characters or unexpected directives within the CableName field.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes API audit logs for unusual object modifications related to Submariner resources.\u003c/li\u003e\n\u003cli\u003eUpgrade Submariner installations to the latest patched version once released by the vendor to remediate the input validation logic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T19:15:32Z","date_published":"2026-09-02T19:15:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-submariner-cve/","summary":"Submariner in cert-auth mode is vulnerable to command injection via improper input validation in the CableName field, allowing unauthenticated remote code execution as root.","title":"Remote Code Execution in Submariner via CRD Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-submariner-cve/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:submariner:submariner:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}