{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/managedcluster-import-controller/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-66795"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["managedcluster-import-controller"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA high-severity vulnerability (CVE-2026-66795) has been identified in the managedcluster-import-controller. The vulnerability exists within the Certificate Signing Request (CSR) auto-approval logic, which fails to adequately validate incoming CSRs. Specifically, the controller does not inspect the signer name or perform necessary decoding of the PEM-encoded x509 CSR before processing.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker who has compromised a privileged service account on a spoke cluster to submit a malicious CSR to the central hub cluster. Because the validation logic is insufficient, the hub cluster may process this request, enabling the attacker to obtain administrative credentials or elevated access rights. Given the criticality of hub-spoke cluster architectures in multi-cluster management, this vulnerability represents a significant risk for unauthorized control over managed environments. Defenders should ensure the controller is patched and monitor for unusual CSR submission patterns originating from existing spoke cluster service accounts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66795 results in privilege escalation, allowing an attacker to move from a compromised spoke cluster service account to administrative control over the central hub cluster. This can facilitate unauthorized access to cluster secrets, control over additional spoke clusters, and potential data exfiltration within the managed environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided security update for the managedcluster-import-controller immediately.\u003c/li\u003e\n\u003cli\u003eReview and audit the permissions associated with all service accounts on spoke clusters that have communication channels with the hub.\u003c/li\u003e\n\u003cli\u003eMonitor CSR request logs on the hub cluster for requests containing anomalous attributes or originating from unexpected spoke cluster service accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T00:51:30Z","date_published":"2026-08-18T00:51:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-17-cve-2026-66795/","summary":"A privilege escalation vulnerability in the managedcluster-import-controller allows a compromised spoke cluster service account to escalate privileges on the hub cluster by submitting malformed Certificate Signing Requests.","title":"Privilege Escalation in managedcluster-import-controller","url":"https://feed.craftedsignal.io/briefs/2026-08-17-cve-2026-66795/"}],"language":"en","title":"CraftedSignal Threat Feed - Managedcluster-Import-Controller","version":"https://jsonfeed.org/version/1.1"}