CVE-2026-66783: Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref

Published Jul 27, 2026
·
Updated

A flaw was found in the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.

Other sources

GetImagePath returns imageOverrides[component] verbatim with zero validation — no registry allow-list, no digest requirement, no signature check. The resulting image runs with Privileged: true, Capabilities: ALL, hostNetwork, RW hostPath mounts, on every node (route-agent) including control-plane nodes. A cluster-admin or anyone who can patch the Submariner CR can point any component to a malicious image and achieve privileged code execution across the entire cluster.

Source: Project Glasswing AI-SAST audit of submariner-io/submariner-operator. Finding ID: FIND-006 Assurance: machineverified

Red Hat

Affected Software

2 affected components
Red Hat Advanced Cluster Management for Kubernetes
submariner-operator

Event History

Jul 27, 2026
Data Sourced
via Red Hat·03:44 PM
DescriptionSeverityAffected Software
Aug 18, 2026
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Dec 17, 58638
Event
via NVD·01:32 AM

Frequently Asked Questions

1

Who can realistically exploit this issue?

Clusters are exposed when a cluster administrator or another user can modify the Submariner Custom Resource. The issue is local (AV:L) and requires high privileges (PR:H), so an unauthenticated remote attacker is not described by the available data.

2

What does an attacker need to do to exploit it?

An attacker needs permission to modify the Submariner CR and must provide a malicious image path. The operator does not validate that path, allowing deployment of the attacker-controlled image.

3

What is the likely impact of successful exploitation?

Successful exploitation can execute arbitrary code with elevated privileges throughout the cluster, including on control-plane nodes. The stated impact includes high confidentiality, integrity, and availability effects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203