在 Submariner 操作器(operator)中发现了一个安全漏洞。该漏洞会导致 Submariner 自定义资源(CR)规范中暴露出长期有效的代理(broker)服务账户(Service Account, SA)的 bearer token。攻击者若能够访问集群的 etcd 数据库,或通过 命令获取相关资源,便可能窃取该 token。一旦持有此 token,攻击者即可获得对整个服务网格(mesh network)的完全控制权限,从而未经授权地管理网络资源,例如端点(endpoints)和密钥(secrets
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66780 | 9.9 CRITICAL | Submariner-operator: submariner-operator: flat broker trust model grants every spoke full |
| CVE-2026-12564 | 9.6 CRITICAL | Automation-controller: automation-controller: kubernetes service account token exfiltratio |
| CVE-2026-18963 | 9.1 CRITICAL | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentia |
| CVE-2026-66793 | 8.8 HIGH | Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary containe |
| CVE-2026-75924 | 8.7 HIGH | Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants clust |
| CVE-2026-66783 | 8.2 HIGH | Submariner-operator: submariner-operator: arbitrary image override enables privileged code |
| CVE-2026-71365 | 7.7 HIGH | Awx: webhook status callback ssrf leaks the git pat |
| CVE-2026-15571 | 7.3 HIGH | Keycloak-services: keycloak-services: predictable account-linking hash enables account tak |
| CVE-2026-66781 | 6.5 MEDIUM | Submariner-operator: submariner-operator: ipsec psk stored cleartext in submariner cr spec |
| CVE-2026-75032 | 6.3 MEDIUM | Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder |
| CVE-2026-75485 | 5.5 MEDIUM | Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect redaction of |
| CVE-2026-73834 | 5.5 MEDIUM | Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redact |
| CVE-2026-19608 | 5.3 MEDIUM | Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy |
No comments yet