Red Hat ACMM Submariner-Operator Escalation via Unvalidated Image Path
CVE-2026-66783 Published on August 18, 2026
Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.
Vulnerability Analysis
CVE-2026-66783 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 22 days later.
Weakness Type
Products Associated with CVE-2026-66783
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.
Affected Versions
Red Hat Advanced Cluster Management for Kubernetes 2.17:- Version 1788105072 and below * is unaffected.
- Version 1788073481 and below * is unaffected.