Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources. | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. |
| Title | cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount | Azure Data Factory Information Disclosure Vulnerability |
| First Time appeared |
Microsoft
Microsoft azure Data Factory |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:microsoft:azure_data_factory:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Data Factory |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources. | |
| Title | cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-20T22:02:55.472Z
Reserved: 2026-07-27T19:02:26.600Z
Link: CVE-2026-66800
No data.
Status : Received
Published: 2026-08-20T22:17:56.043
Modified: 2026-08-20T22:17:56.043
Link: CVE-2026-66800
OpenCVE Enrichment
Updated: 2026-08-12T16:00:04Z