A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.
Metrics
Affected Vendors & Products
References
History
Sat, 05 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.17::el9 | |
| References |
|
Wed, 02 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets | Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets |
| First Time appeared |
Redhat
Redhat acm |
|
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
|
Mon, 24 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Submariner
Submariner submariner |
|
| Vendors & Products |
Submariner
Submariner submariner |
Sat, 22 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node. | |
| Title | submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-09-02T17:57:19.436Z
Updated: 2026-09-05T01:01:30.464Z
Reserved: 2026-07-27T17:51:24.885Z
Link: CVE-2026-66786
Updated: 2026-09-05T01:01:26.612Z
Status : Awaiting Analysis
Published: 2026-09-02T18:21:10.517
Modified: 2026-09-05T01:16:49.053
Link: CVE-2026-66786