<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Submariner - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/submariner/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 20 Aug 2026 21:19:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/submariner/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Lighthouse Cross-Namespace Resource Injection Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-lighthouse-vulnerability/</link><pubDate>Thu, 20 Aug 2026 21:19:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-lighthouse-vulnerability/</guid><description>A vulnerability in Submariner Lighthouse allows a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into peer cluster namespaces, leading to potential privilege escalation.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-66788) exists in Submariner Lighthouse, a multi-cluster service discovery tool. The flaw allows an attacker who has successfully compromised a spoke cluster to exploit the resource injection mechanism. The vulnerability occurs because the destination namespace for resource injection is determined by an attacker-controlled label or annotation on the broker object rather than being validated against allowed scopes. By manipulating these labels or annotations, an attacker can force the injection of unauthorized EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including sensitive system namespaces such as kube-system and openshift-*. This flaw enables cross-namespace unauthorized resource creation, effectively allowing an attacker to hijack service traffic or escalate privileges across the connected cluster network. Given the CVSS score of 9.9, this vulnerability poses a significant risk to the integrity and security of multi-cluster environments managed by Submariner.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to perform cross-namespace resource injection in a multi-cluster environment. This can result in unauthorized service discovery, traffic interception, or privilege escalation by deploying malicious service definitions into critical system namespaces. The scope of impact includes any infrastructure using Submariner Lighthouse for cross-cluster service discovery.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams managing Submariner Lighthouse:</p>
<ul>
<li>Upgrade Submariner Lighthouse to the patched version that implements validation for namespace-related labels and annotations on broker objects.</li>
<li>Audit existing Kubernetes RBAC configurations and Submariner broker permissions to ensure that compromised spoke clusters do not have excessive write permissions to the broker object's metadata.</li>
<li>Monitor logs for unusual modifications to EndpointSlice or ServiceImport resources originating from external clusters.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cloud-native</category><category>kubernetes</category><category>privilege-escalation</category><category>submariner</category></item></channel></rss>