PatchSiren cyber security CVE debrief
CVE-2026-66793 Red Hat CVE debrief
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-27
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-27
Who should care
Red Hat Advanced Cluster Management for Kubernetes users and administrators, Kubernetes security teams, IT professionals managing cluster resources, and operators responsible for maintaining system configurations and ensuring compliance with organizational security policies and procedures. Additionally, security teams should assess and prioritize patching based on risk, and consider implementing compensating controls for exposed systems while remediation is scheduled and verified. Those managing cluster resources should review and update governance-policy-addon-controller to the latest version, and monitor for and apply Red Hat security patches related to this CVE. This should be done in coordination with IT professionals who manage cluster resources and ensure that appropriate defensive measures are in place to mitigate potential impacts. Furthermore, affected product deployments in managed environments should be confirmed and assigned an owner for follow-up, with a focus on verifying and updating governance-policy-addon-controller to the latest version. Those responsible for maintaining system configurations should also review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. Finally, it is crucial that all relevant parties, including Kubernetes security teams and IT professionals, work together to implement these measures effectively and ensure the security of their systems. This may involve conducting a thorough review of current configurations, identifying potential vulnerabilities, and taking proactive steps to mitigate risks. By taking a comprehensive and coordinated approach, organizations can minimize the impact of this vulnerability and protect their systems from potential threats. With these considerations in mind, organizations should take immediate action to address this vulnerability and ensure the security and integrity of their systems and data. This includes verifying and updating governance-policy-addon-controller to the latest version, implementing compensating controls for exposed systems, and monitoring,
Technical summary
The governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes is vulnerable to an exploit allowing a user with specific permissions to override the governance-policy container image. This can lead to running a controlled image with cluster-admin privileges on the managed cluster, enabling arbitrary code execution and privilege escalation. Affected product deployments should be confirmed in managed environments and assigned an owner for follow-up. Those managing cluster resources should review and update governance-policy-addon-controller to the latest version and monitor for and apply Red Hat security patches related to this CVE.
Defensive priority
High priority due to potential for arbitrary code execution and privilege escalation in a Kubernetes environment.
Recommended defensive actions
- Inventory and assess exposure of Red Hat Advanced Cluster Management for Kubernetes installations to this vulnerability.
- Restrict permissions for annotating ManagedClusterAddOn resources to trusted users.
- Monitor for and apply Red Hat security patches related to this CVE.
- Implement compensating controls such as network restrictions or enhanced logging.
- Verify and update governance-policy-addon-controller to the latest version.
Evidence notes
Evidence from Red Hat and NVD indicates a flaw in governance-policy-addon-controller. User permissions to annotate ManagedClusterAddOn can be exploited to run a controlled image with cluster-admin privileges.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66793 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66793
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66793 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66793
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60386
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60387
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60388
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60389
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60390
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60391
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-66793
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.