Submariner Operator Exposes Unencrypted IPsec PSK
CVE-2026-66781 Published on August 18, 2026
Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 22 days later.
Weakness Type
Exposed Dangerous Method or Function
The software provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Products Associated with CVE-2026-66781
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.
Affected Versions
Red Hat Advanced Cluster Management for Kubernetes 2.11:- Version 1787689013 and below * is unaffected.
- Version 1787365971 and below * is unaffected.
- Version 1787362756 and below * is unaffected.
- Version 1787362733 and below * is unaffected.
- Version 1787362694 and below * is unaffected.
- Version 1787362658 and below * is unaffected.
- Version 1788105072 and below * is unaffected.
- Version 1788073481 and below * is unaffected.