PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66795 Red Hat CVE debrief

A flaw in the managedcluster-import-controller allows a privileged service account on a spoke cluster to submit a malicious Certificate Signing Request (CSR). This CSR auto-approval logic vulnerability can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster. Successful exploitation requires validation of the signer name and decoding of the PEM-encoded x509 CSR, which was not properly inspected.

Vendor
Red Hat
Product
multicluster engine for Kubernetes 2.11
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-29
Advisory published
2026-08-17
Advisory updated
2026-09-29

Who should care

Defenders managing Kubernetes clusters, particularly those using Red Hat's multicluster engine, should assess exposure and verify their configurations. Roles including cluster administrators, security teams, and DevOps engineers should review CSR validation processes and ensure that service accounts are properly secured.

Why it matters

CVE-2026-66795 allows a privileged service account on a spoke cluster to potentially escalate privileges on the hub cluster via malicious CSR submissions. Defenders should verify and restrict CSR submissions, review validation logic, and ensure least privilege for service accounts. The vulnerability's impact requires verification from official sources, and its exploitation instances are currently unknown.

  • Potential privilege escalation to administrative credentials on the hub cluster
  • Need for verification of CSR validation logic in place
  • Possible impact on cluster security posture if not properly mitigated
  • Requirement for enhanced monitoring of CSR submissions and service account activities

Technical summary

The managedcluster-import-controller flaw allows a privileged service account on a spoke cluster to submit a malicious CSR, potentially leading to privilege escalation on the hub cluster. The vulnerability arises from improper validation of incoming CSRs, specifically not inspecting the signer name or decoding the PEM-encoded x509 CSR. This issue impacts clusters using Red Hat's multicluster engine, particularly those with service accounts on spoke clusters that have elevated privileges. Defenders should focus on verifying CSR validation logic, ensuring least privilege for service accounts, and monitoring for suspicious CSR activities to mitigate potential risks.

Defensive priority

Defenders should prioritize verifying and restricting CSR submissions from spoke clusters, reviewing and enhancing the validation logic for signer names and PEM-encoded x509 CSRs, and ensuring that service accounts on spoke clusters have the least privilege necessary.

Recommended defensive actions

  • Verify and restrict CSR submissions from spoke clusters
  • Review and enhance validation logic for signer names and PEM-encoded x509 CSRs
  • Ensure service accounts on spoke clusters have the least privilege necessary
  • Monitor for unusual CSR activity and potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and references to affected vendor errata. However, the corpus does not establish specific versions affected or fixed, exploitation instances, or detailed impact beyond potential privilege escalation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66795 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66795

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66795 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66795

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.