Security Advisory

CVE-2026-66782

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-18 17:06:00
Last updated 2026-08-18 19:53:15
Assigner redhat
CVSS score 7.8
State PUBLISHED

Description

A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl get` commands could obtain this token. The possession of this token grants full control over the mesh network, enabling unauthorized management of network resources such as endpoints and secrets.