Skip to main content
EPSS 0.5%top 60%

CVE-2026-66795: Improper Certificate Validation in Red Hat multicluster engine for Kubernetes 2.10

0
Critical
Published: 08/17/2026 (08/17/2026, 20:45:33 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: multicluster engine for Kubernetes 2.10

Description

CVE-2026-66795 is a critical vulnerability in Red Hat OpenShift Multicluster Engine's managedcluster-import-controller. The flaw involves improper validation of Certificate Signing Requests (CSRs) in the auto-approval logic, specifically failing to inspect the signer name or decode the PEM-encoded x509 CSR. This allows a privileged service account on a spoke cluster to submit a malicious CSR and escalate privileges to obtain administrative credentials on the hub cluster. No effective mitigation or patch is currently available that meets Red Hat's criteria for ease of use and stability.

CVSS v3.1

Score 9.9critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:30:13 UTC

Technical Analysis

The managedcluster-import-controller component of Red Hat OpenShift Multicluster Engine improperly validates incoming CSRs by not verifying the signer name or decoding the PEM-encoded x509 CSR. This vulnerability enables a privileged service account on a spoke cluster to submit a malicious CSR that can be auto-approved, leading to privilege escalation. Successful exploitation grants the attacker cluster-admin privileges on the hub cluster, compromising the security of the multicluster environment. The issue is tracked as CWE-295 (Improper Certificate Validation) and carries a CVSS 3.1 score of 9.9, indicating critical severity.

Potential Impact

Exploitation of this vulnerability allows a compromised privileged service account on a spoke cluster to escalate privileges and obtain administrative credentials on the hub cluster. This results in a complete compromise of the hub cluster's security, including confidentiality, integrity, and availability. The vulnerability affects the overall security posture of the multicluster environment, posing a significant risk to organizations using Red Hat OpenShift Multicluster Engine.

Mitigation Recommendations

As per the Red Hat advisory, no mitigation or patch currently meets the criteria for ease of use, applicability, or stability. Users should monitor the official Red Hat advisory for updates. Until a fix is available, restricting access to privileged service accounts on spoke clusters and limiting exposure of the managedcluster-import-controller may reduce risk, but no definitive mitigation is provided by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-w9c6-w29v-4vp6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-66795"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6a838c36bf8831d539b4b17f

Added to database: 08/17/2026, 22:33:26 UTC

Last enriched: 09/29/2026, 21:30:13 UTC

Last updated: 10/02/2026, 14:55:59 UTC

Views: 53

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses