CVE-2026-66793

Summary

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-20: Improper Input Validation

Workarounds

To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References