A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
History

Thu, 03 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2 cpe:/a:redhat:acm:2.17::el9
References

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag
Weaknesses CWE-1104
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
Title Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace
First Time appeared Redhat
Redhat acm
Weaknesses CWE-284
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-08-20T18:15:37.408Z

Updated: 2026-09-03T04:41:39.269Z

Reserved: 2026-07-27T17:51:24.885Z

Link: CVE-2026-66788

cve-icon Vulnrichment

Updated: 2026-08-20T18:52:27.248Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-20T19:16:58.823

Modified: 2026-09-03T13:06:01.203

Link: CVE-2026-66788

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-20T17:20:00Z

Links: CVE-2026-66788 - Bugzilla