<Vulnerability name="CVE-2026-66788">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-20T17:20:00</PublicDate>
    <Bugzilla id="2507533" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507533" xml:lang="en:us">
lighthouse: Dockerfile build stages use end-of-life Fedora 40 referenced by mutable tag
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>3.7</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1104</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
    </Details>
    <Statement xml:lang="en:us">
Important: This flaw in Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to inject EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including critical system namespaces. The `lighthouse-agent` service account uses an attacker-controlled label for the destination namespace without validation, enabling potential privilege escalation or service disruption across the cluster federation.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-09-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63016">RHSA-2026:63016</Advisory>
        <Package name="rhacm2/lighthouse-agent-rhel9">rhacm2/lighthouse-agent-rhel9:1788023916</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-09-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63016">RHSA-2026:63016</Advisory>
        <Package name="rhacm2/lighthouse-coredns-rhel9">rhacm2/lighthouse-coredns-rhel9:1788023940</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-09-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63016">RHSA-2026:63016</Advisory>
        <Package name="rhacm2/subctl-rhel9">rhacm2/subctl-rhel9:1788105072</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-09-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:63016">RHSA-2026:63016</Advisory>
        <Package name="rhacm2/submariner-rhel9-operator">rhacm2/submariner-rhel9-operator:1788073481</Package>
    </AffectedRelease>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-66788
https://nvd.nist.gov/vuln/detail/CVE-2026-66788
    </References>
</Vulnerability>