PatchSiren cyber security CVE debrief
CVE-2026-66794 Red Hat CVE debrief
A critical vulnerability was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This flaw allows an unauthenticated attacker to bypass authentication and authorization checks by manipulating URL path segments, potentially leading to unauthorized access to internal services. Cluster administrators and security teams should assess their exposure and prioritize remediation based on the affected component and potential operational impacts. The vulnerability enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.
- Vendor
- Red Hat
- Product
- Multicluster Engine for Kubernetes
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-29
Who should care
Cluster administrators and security teams responsible for managing Multicluster Engine for Kubernetes deployments should assess their exposure and prioritize remediation based on the affected component and potential operational impacts. This includes teams responsible for vulnerability management, incident response, and ensuring the security of cluster environments.
Why it matters
CVE-2026-66794 is a critical vulnerability in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. An unauthenticated attacker can bypass authentication and authorization checks, potentially leading to unauthorized access to internal services. Cluster administrators and security teams should assess their exposure and prioritize remediation.
- Potential unauthorized access to internal services
- Possible information disclosure
- Risk of further compromise of the cluster environment
- Verification of affected versions and remediation status is required
Technical summary
The `cluster-proxy-addon` component of Multicluster Engine for Kubernetes is vulnerable to an authentication bypass attack. An unauthenticated attacker can manipulate URL path segments to proxy requests to arbitrary services across any managed cluster, potentially leading to unauthorized access to internal services. This vulnerability allows unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment. Cluster administrators and security teams should assess their exposure and prioritize remediation.
Defensive priority
High priority remediation is recommended for clusters using the affected component.
Recommended defensive actions
- Review and apply security patches for the affected component
- Restrict access to the user-facing route
- Monitor cluster activity for suspicious requests
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability was reported by an unknown source and is tracked by CVE-2026-66794. The affected vendor is Red Hat, and the product is Multicluster Engine for Kubernetes. Evidence is limited to the supplied source corpus and CVE metadata. Defenders should verify affected versions, review vendor guidance, and assess exposure based on available information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66794 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66794
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66794 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66794
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59556
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59557
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59558
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59559
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59579
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:59593
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-66794
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.