CVE-2026-66788 is a vulnerability in Red Hat Acm
Published on August 20, 2026
Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
Vulnerability Analysis
CVE-2026-66788 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Timeline
Reported to Red Hat.
Made public. 24 days later.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-66788 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-66788
Want to know whenever a new CVE is published for Red Hat Acm? stack.watch will email you.