CVE-2026-66794
Last modified
CVE-2026-66794 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | multicluster engine for Kubernetes 2.1 | All versions |
| Red Hat | multicluster engine for Kubernetes 2.11 | All versions |
| Red Hat | multicluster engine for Kubernetes 2.17 | All versions |
| Red Hat | multicluster engine for Kubernetes 2.6 | All versions |
| Red Hat | multicluster engine for Kubernetes 2.8 | All versions |
| Red Hat | multicluster engine for Kubernetes 2.9 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-66794?
How severe is CVE-2026-66794?
How do I fix CVE-2026-66794?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66788A flaw was found in Lighthouse. A remote attacker, by compro…3.7
- CVE-2026-66789Rejected reason: This CVE ID was assigned in error as a dupl…
- CVE-2026-6679A heap buffer overflow could occur in the DTLS 1.3 ACK seria…7.5
- CVE-2026-66790Rejected reason: This CVE ID was assigned in error as a dupl…
- CVE-2026-66792A flaw was found in the multicloud-operators-subscription co…9.9
- CVE-2026-66793A flaw was found in the governance-policy-addon-controller c…8.8
- CVE-2026-66795A flaw was found in the managedcluster-import-controller. Th…9.9
- CVE-2026-66797Improper access control in CloudStack's annotation functiona…5.4
- CVE-2026-66798Use after free in Microsoft Edge (Chromium-based) allows an …4.3
- CVE-2026-66799Heap-based buffer overflow in Windows Key Guard allows an au…7.8
- CVE-2026-66800Server-side request forgery (ssrf) in Azure Data Factory all…7.5
- CVE-2026-66802Concurrent execution using shared resource with improper syn…8.1
Are you affected by CVE-2026-66794?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
