Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster. | |
| Title | Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-17T20:45:33.786Z
Reserved: 2026-07-27T17:51:24.886Z
Link: CVE-2026-66795
No data.
Status : Received
Published: 2026-08-17T21:16:47.163
Modified: 2026-08-17T21:16:47.163
Link: CVE-2026-66795
No data.
OpenCVE Enrichment
No data.
-
CWE-295
Improper Certificate Validation