CVE-2026-66783
CVE-2026-66783: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium4.4
Medium [CVE-2026-66783] Release workflow consumes same-org composite action via mutable @devel branch ref
CVE-2026-66783Source published Source updated
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image. This is due to a lack of image validation when overriding component images, enabling the deployment of malicious images with extensive privileges. Red Hat severity: Important — CVSS 4.4 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-1357. Red Hat fixing advisory: RHSA-2026:63016. Affected product named by the advisory…
- Affected products in this advisory
- Red Hat Advanced Cluster Management for Kubernetes 2.17
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- rhacm2/subctl-rhel9:1788105072
- rhacm2/submariner-rhel9-operator:1788073481
- RHSA-2026:63016
- Mitigation guidance
- To mitigate this issue, restrict access to cluster-admin roles and carefully control permissions for users or service accounts that can modify Submariner Custom Resources. Ensure that only trusted and authorized personnel have the ability to patch Submariner CRs, thereby preventing the injection of malicious images.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.