CVE-2026-66793

Summary

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.111787683327 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.131787259078 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.141787080755 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.151787238535 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.161787080753 < *unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.171787227696 < *unaffected

Weaknesses

  • CWE-20: Improper Input Validation

Workarounds

To mitigate this issue, restrict users' ability to annotate ManagedClusterAddOn resources within the hub cluster. Ensure that only trusted administrators have namespace-level annotate permissions on these resources. Regularly review and audit permissions related to ManagedClusterAddOn resources to prevent unauthorized modifications. If a service is restarted or reloaded, these permission changes will persist.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References