Junglewise Threat Intelligence

CVE-2026-66787: Red Hat Advanced Cluster Management Lighthouse IP validation bypass

CVE-2026-66787 · Severity: medium · CVSS 5.4 · Published 2026-08-20

Vendors: Red Hat.

Executive brief

Red Hat Advanced Cluster Management for Kubernetes includes a lighthouse component that provides DNS resolution for cross-cluster services. A flaw in IP address validation allows a compromised cluster to inject malicious IP addresses into service endpoints, redirecting legitimate traffic to attacker-controlled servers. This could allow attackers to intercept and modify service traffic between clusters, exposing sensitive data and enabling service manipulation.

Technical details

The vulnerability exists in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes, specifically in the handling of EndpointSlice objects. The root cause is insufficient validation of advertised IP addresses within these objects. An attacker with access to a spoke cluster can create malicious EndpointSlices containing attacker-controlled IP addresses. When other clusters' lighthouse DNS resolves service queries, it uses these poisoned endpoints, redirecting legitimate traffic to malicious locations. This enables transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications without requiring network-level interception, leading to information disclosure and data manipulation. A patch is available as part of Submariner v0.24 and Red Hat Advanced Cluster Management for Kubernetes v2.17.

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes prior to v2.17

Timeline

  • 2026-08-20: disclosed
  • 2026-09-03: advisory: RHSA-2026:63016 published with fix in Submariner v0.24

References