<Vulnerability name="CVE-2026-66808">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-06T20:21:07</PublicDate>
    <Bugzilla id="2509774" url="https://bugzilla.redhat.com/show_bug.cgi?id=2509774" xml:lang="en:us">
hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.7</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-88</CWE>
    <Details xml:lang="en:us" source="Mitre">
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in hypershift-addon-operator. A hub-cluster administrator with write access to the hypershift-operator-install-flags ConfigMap can inject malicious command-line arguments into the privileged install Job. This vulnerability, known as argument injection, allows the attacker to pull arbitrary container images and gain full administrative control (cluster-admin code execution) on managed spoke clusters.
    </Details>
    <Statement xml:lang="en:us">
This Important flaw in Multicluster Engine for Kubernetes allows a hub-cluster namespace administrator with write access to the `hypershift-operator-install-flags` ConfigMap to inject arbitrary command-line arguments into a privileged install Job. This enables privilege escalation to cluster-admin on managed spoke clusters, bypassing security boundaries within the multi-cluster environment.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <AffectedRelease impact="important" cpe="cpe:/a:redhat:multicluster_engine:2.10::el9">
        <ProductName>multicluster engine for Kubernetes 2.10</ProductName>
        <ReleaseDate>2026-08-12T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:54432">RHSA-2026:54432</Advisory>
        <Package name="multicluster-engine/hypershift-addon-rhel9-operator">multicluster-engine/hypershift-addon-rhel9-operator:1786548381</Package>
    </AffectedRelease>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-66808
https://nvd.nist.gov/vuln/detail/CVE-2026-66808
https://github.com/stolostron/hypershift-addon-operator/pull/766
    </References>
</Vulnerability>