Red Hat ACMM Submariner-Operator Escalation via Unvalidated Image Path
CVE-2026-66783 Published on August 18, 2026
Submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
Vulnerability Analysis
CVE-2026-66783 can be exploited with local system access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public. 22 days later.
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Products Associated with CVE-2026-66783
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.