Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster. | |
| Title | Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace | |
| First Time appeared |
Redhat
Redhat acm |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:/a:redhat:acm:2 | |
| Vendors & Products |
Redhat
Redhat acm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-20T18:52:30.583Z
Reserved: 2026-07-27T17:51:24.885Z
Link: CVE-2026-66788
Updated: 2026-08-20T18:52:27.248Z
Status : Received
Published: 2026-08-20T19:16:58.823
Modified: 2026-08-20T19:16:58.823
Link: CVE-2026-66788
No data.
OpenCVE Enrichment
No data.