Lighthouse Namespace Injection for Unauthorized EndpointSlice/ServiceImport
CVE-2026-66788 Published on August 20, 2026
Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
Vulnerability Analysis
CVE-2026-66788 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 24 days later.
Weakness Type
Use of Unmaintained Third Party Components
The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.
Products Associated with CVE-2026-66788
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.
Affected Versions
Red Hat Advanced Cluster Management for Kubernetes 2.17:- Version 1788023916 and below * is unaffected.
- Version 1788023940 and below * is unaffected.
- Version 1788105072 and below * is unaffected.
- Version 1788073481 and below * is unaffected.