Executive brief
Submariner is a tool used to connect Kubernetes clusters across networks. A vulnerability in its certificate authentication mode allows a malicious cluster to inject arbitrary configuration directives and commands through specially crafted cluster names. An attacker exploiting this can execute arbitrary code with root privileges on the gateway node that manages inter-cluster connections.
Technical details
This is a configuration injection vulnerability in Submariner's cert-auth mode. The vulnerability exists because the connection configuration is built from free-form strings sourced from a Custom Resource Definition (CRD) without proper validation or sanitization. An attacker controlling a malicious cluster can publish a crafted CableName containing newlines and ipsec.conf directives that are injected into the configuration file. This can include leftupdown hooks that allow arbitrary command execution. The attack requires the malicious cluster to be federated with the target cluster and able to publish resources to the CRD. The impact is remote code execution as root on the gateway node.
Affected products
- Submariner Submariner
Timeline
- 2026-09-02: disclosed