{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/red-hat-advanced-cluster-management-for-kubernetes-2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-66780"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat Advanced Cluster Management for Kubernetes 2"],"_cs_severities":["critical"],"_cs_tags":["kubernetes","cloud","privilege-escalation","rbac"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA critical vulnerability (CVE-2026-66780) exists within the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes 2. The issue stems from the \u003ccode\u003esubmariner-k8s-broker-cluster\u003c/code\u003e Role, which is automatically assigned to joined clusters in a cluster mesh architecture. This role contains excessive permissions that violate the principle of least privilege. Specifically, an attacker who gains control over a single member cluster within the mesh can leverage these elevated permissions to modify shared network configuration objects. By overwriting endpoint information for other clusters in the broker, the attacker can redirect inter-cluster traffic through their compromised node. This facilitates large-scale Man-in-the-Middle (MITM) attacks against internal services communicating across the mesh. Given the potential for complete traffic interception within a multi-cluster Kubernetes environment, this vulnerability poses a severe risk to data confidentiality and integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to a single Kubernetes cluster member participating in the Submariner mesh.\u003c/li\u003e\n\u003cli\u003eAttacker leverages local cluster privileges to impersonate the service account associated with the \u003ccode\u003esubmariner-k8s-broker-cluster\u003c/code\u003e Role.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates against the central Kubernetes API server managing the broker.\u003c/li\u003e\n\u003cli\u003eAttacker issues a \u003ccode\u003ePUT\u003c/code\u003e or \u003ccode\u003ePATCH\u003c/code\u003e request to the broker's API endpoints to modify \u003ccode\u003eEndpoint\u003c/code\u003e or \u003ccode\u003eCluster\u003c/code\u003e custom resources.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious endpoint metadata, pointing other clusters' tunnel traffic to the attacker-controlled cluster IP.\u003c/li\u003e\n\u003cli\u003eSubmariner controllers on other clusters automatically update their routing tables based on the malicious broker data.\u003c/li\u003e\n\u003cli\u003eInter-cluster traffic is routed through the attacker-controlled node, enabling decryption or modification of the data stream.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full interception, modification, or denial-of-service of inter-cluster network traffic across the entire mesh. This affects all Red Hat Advanced Cluster Management for Kubernetes 2 deployments utilizing the Submariner add-on, potentially impacting any sector relying on multi-cluster Kubernetes orchestration for production workloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate audit of all Submariner service account permissions in your cluster broker.\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003ePatch the submariner-operator component to the latest vendor-provided version that restricts the \u003ccode\u003esubmariner-k8s-broker-cluster\u003c/code\u003e role.\u003c/li\u003e\n\u003cli\u003eImplement Kubernetes API audit logging to monitor for anomalous modifications to \u003ccode\u003eEndpoint\u003c/code\u003e objects by service accounts.\u003c/li\u003e\n\u003cli\u003eReview all RBAC policies for cross-cluster communication channels to ensure they follow the principle of least privilege.\u003c/li\u003e\n\u003cli\u003eUse network policies to restrict cluster-to-cluster traffic to only explicitly required services, reducing the blast radius of a potential MITM scenario.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-18T18:55:26Z","date_published":"2026-08-18T18:55:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-submariner-rbac-flaw/","summary":"A critical RBAC vulnerability in the submariner-operator component allows a compromised Kubernetes cluster to overwrite endpoint configurations, enabling inter-cluster traffic interception.","title":"Excessive RBAC Permissions in Submariner-Operator","url":"https://feed.craftedsignal.io/briefs/2026-08-submariner-rbac-flaw/"}],"language":"en","title":"CraftedSignal Threat Feed - Red Hat Advanced Cluster Management for Kubernetes 2","version":"https://jsonfeed.org/version/1.1"}