Red Hat ACMM Submariner-Operator Escalation via Unvalidated Image Path
CVE-2026-66783 Published on August 18, 2026

Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-66783 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
NONE

Timeline

Reported to Red Hat.

Made public. 22 days later.

Weakness Type

CWE-1357

Products Associated with CVE-2026-66783

Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.

 

Affected Versions

Red Hat Advanced Cluster Management for Kubernetes 2.17: Red Hat Advanced Cluster Management for Kubernetes 2.17: Red Hat Advanced Cluster Management for Kubernetes 2: Red Hat Advanced Cluster Management for Kubernetes 2: