Vendor
critical
advisory
Remote Code Execution in Submariner via CRD Injection
2 TTPs 1 CVESubmariner in cert-auth mode is vulnerable to command injection via improper input validation in the CableName field, allowing unauthenticated remote code execution as root.
Submariner
remote-code-execution
kubernetes
cve
cloud
2t
1c
critical
advisory
Lighthouse Cross-Namespace Resource Injection Vulnerability
1 TTP 1 CVEA vulnerability in Submariner Lighthouse allows a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into peer cluster namespaces, leading to potential privilege escalation.
Lighthouse
cloud-native
kubernetes
privilege-escalation
submariner
1t
1c
critical
advisory
Critical Traffic Redirection Vulnerability in Submariner
2 TTPs 1 CVECVE-2026-66785 allows a malicious Kubernetes cluster to intercept inter-cluster traffic by injecting crafted network endpoints into the Submariner control plane.
Submariner
kubernetes
networking
cve-2026-66785
traffic-interception
2t
1c
high
threat
CVE-2026-66782: Token Exposure in Submariner Operator
1 TTP 1 CVEThe Submariner operator exposes long-lived service account tokens within Custom Resource specifications, allowing attackers with RBAC access to gain full control over mesh network resources.
exploited
Submariner operator
credential-access
kubernetes
cloud-native
1t
1c