{
  "threat_severity" : "Important",
  "public_date" : "2026-08-13T13:30:00Z",
  "bugzilla" : {
    "description" : "console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler",
    "id" : "2508665",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2508665"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.7",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.", "A flaw was found in the console component. An authenticated user can exploit a Server-Side Request Forgery (SSRF) vulnerability by manipulating the `towerHost` parameter when accessing the `/ansibletower` handler. This allows the user to bypass pathname validation and access arbitrary internal or external hosts. The primary consequence is the exfiltration of full HTTP responses, leading to information disclosure from the affected system." ],
  "statement" : "This Important vulnerability in the console component allows an authenticated Red Hat Advanced Cluster Management (ACM) console user to perform Server-Side Request Forgery (SSRF). This enables the attacker to access arbitrary internal or external hosts from the hub's network position and exfiltrate full HTTP responses, bypassing existing pathname restrictions due to control over the hostname.",
  "affected_release" : [ {
    "product_name" : "multicluster engine for Kubernetes 2.1",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59557",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.10::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1787079364"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.11",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57194",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.11::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1786911977"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.17",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59593",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.17::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1786668856"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.6",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59579",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.6::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1787264250"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.8",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59558",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.8::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1787259048"
  }, {
    "product_name" : "multicluster engine for Kubernetes 2.9",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59559",
    "cpe" : "cpe:/a:redhat:multicluster_engine:2.9::el9",
    "package" : "multicluster-engine/console-mce-rhel9:1787079359"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.11",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60387",
    "cpe" : "cpe:/a:redhat:acm:2.11::el9",
    "package" : "rhacm2/console-rhel9:1787687062"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.13",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60390",
    "cpe" : "cpe:/a:redhat:acm:2.13::el9",
    "package" : "rhacm2/console-rhel9:1787339249"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.14",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60388",
    "cpe" : "cpe:/a:redhat:acm:2.14::el9",
    "package" : "rhacm2/console-rhel9:1787339248"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.15",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60389",
    "cpe" : "cpe:/a:redhat:acm:2.15::el9",
    "package" : "rhacm2/console-rhel9:1787341780"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.16",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57191",
    "cpe" : "cpe:/a:redhat:acm:2.16::el9",
    "package" : "rhacm2/console-rhel9:1786908361"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.17",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60386",
    "cpe" : "cpe:/a:redhat:acm:2.17::el9",
    "package" : "rhacm2/console-rhel9:1787335105"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-66804\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-66804\nhttps://issues.redhat.com/browse/ACM-38691" ],
  "name" : "CVE-2026-66804",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}