GHSA-xh6j-xcjj-j38gHighCVSS 8.8
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-66793
- https://access.redhat.com/security/cve/CVE-2026-66793
- https://bugzilla.redhat.com/show_bug.cgi?id=2507538
- https://access.redhat.com/errata/RHSA-2026:60386
- https://access.redhat.com/errata/RHSA-2026:60389
- https://access.redhat.com/errata/RHSA-2026:60390
- https://access.redhat.com/errata/RHSA-2026:60387
- https://access.redhat.com/errata/RHSA-2026:60388
- https://access.redhat.com/errata/RHSA-2026:60391
- https://github.com/advisories/GHSA-xh6j-xcjj-j38g