VDB

CVE-2026-66787

CVE-2026-66787 PUBLISHED CVSS 5.4 MEDIUM

Reported by redhat · Published August 20, 2026

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.

Risk Scores

CVSS 3.1
5.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected Products

VendorProductVersions
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788023916
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788023940
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788105072
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788073481
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788105072
Red HatRed Hat Advanced Cluster Management for Kubernetes 2
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788023916
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788023940
Red HatRed Hat Advanced Cluster Management for Kubernetes 2
Red HatRed Hat Advanced Cluster Management for Kubernetes 2
Red HatRed Hat Advanced Cluster Management for Kubernetes 2
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171788073481

Timeline

  • Aug 20, 2026 CVE Published
  • Aug 21, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Sep 2, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 3, 2026 CVE Updated
  • Sep 4, 2026 Distribution Patch
  • Sep 4, 2026 Security Advisory
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›