CVE-2026-66781
CVE-2026-66781: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium5.4
Medium [CVE-2026-66781] pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication
CVE-2026-66781Source published Source updated
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure. As Custom Resources are not encrypted by default in etcd on OpenShift, and the PSK is identical across all clusters in a mesh, its disclosure via `kubectl get submariner -o yaml` or through must-gather bundles allows an attacker with appropriate permissions to passively decrypt traffic between any two connected clusters.…
- Affected products in this advisory
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- Red Hat Advanced Cluster Management for Kubernetes 2.14
- Red Hat Advanced Cluster Management for Kubernetes 2.15
2 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- rhacm2/submariner-addon-rhel9:1787689013
- rhacm2/submariner-addon-rhel9:1787365971
- rhacm2/submariner-addon-rhel9:1787362756
- rhacm2/submariner-addon-rhel9:1787362733
11 more entries in the full advisory.
- Mitigation guidance
- To mitigate the risk of IPsec pre-shared key (PSK) disclosure, implement strict Kubernetes Role-Based Access Control (RBAC) policies to limit access to Submariner Custom Resources. Ensure that only authorized administrators and systems are granted permissions to view `submariner` Custom Resources within their namespaces. Additionally, exercise caution when collecting and storing diagnostic data, such as must-gather bundles, and when managing GitOps repositories, as these may inadvertently expose the cleartext PSK.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.