Junglewise Threat Intelligence

CVE-2026-66786: Submariner configuration injection leading to remote code execution

CVE-2026-66786 · Severity: critical · CVSS 9.1 · Published 2026-09-02

Executive brief

Submariner is a tool used to connect Kubernetes clusters across networks. A vulnerability in its certificate authentication mode allows a malicious cluster to inject arbitrary configuration directives and commands through specially crafted cluster names. An attacker exploiting this can execute arbitrary code with root privileges on the gateway node that manages inter-cluster connections.

Technical details

This is a configuration injection vulnerability in Submariner's cert-auth mode. The vulnerability exists because the connection configuration is built from free-form strings sourced from a Custom Resource Definition (CRD) without proper validation or sanitization. An attacker controlling a malicious cluster can publish a crafted CableName containing newlines and ipsec.conf directives that are injected into the configuration file. This can include leftupdown hooks that allow arbitrary command execution. The attack requires the malicious cluster to be federated with the target cluster and able to publish resources to the CRD. The impact is remote code execution as root on the gateway node.

Affected products

  • Submariner Submariner

Timeline

  • 2026-09-02: disclosed

References