Submariner Operator Exposes Unencrypted IPsec PSK
CVE-2026-66781 Published on August 18, 2026

Submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure.

Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
LOW

Timeline

Reported to Red Hat.

Made public. 22 days later.

Weakness Type

Exposed Dangerous Method or Function

The software provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.


Products Associated with CVE-2026-66781

Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.

 

Affected Versions

Red Hat Advanced Cluster Management for Kubernetes 2.11: Red Hat Advanced Cluster Management for Kubernetes 2.13: Red Hat Advanced Cluster Management for Kubernetes 2.14: Red Hat Advanced Cluster Management for Kubernetes 2.15: Red Hat Advanced Cluster Management for Kubernetes 2.16: Red Hat Advanced Cluster Management for Kubernetes 2.17: Red Hat Advanced Cluster Management for Kubernetes 2.17: Red Hat Advanced Cluster Management for Kubernetes 2.17: Red Hat Advanced Cluster Management for Kubernetes 2: