CVE-2026-66792Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-08-17); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 108-1708-1808-1908-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-66792 (CVSS 9.9) and two more Red Hat ACM flaws allow full compromise of the managed cluster via privilege escalation. #CVE202666792 #RedHat #Kubernetes #PrivilegeEscalation #ACM #ClusterAdmin https://securityonline.info/red-hat-acm-cluster-privilege-escalation/

    Post summary

    The post announces CVE‑2026‑66792, a high‑severity Red Hat ACM flaw enabling privilege escalation and full cluster compromise, with no evidence of active exploitation or available patches.

    02091590
    13.0K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-66792 (CVSS 9.9): Red Hat ACMの脆弱性により、管理対象クラスタが完全に侵害される可能性がある CVE-2026-66792 (CVSS 9.9): Red Hat ACM Flaw Allows Full Compromise of the Managed Cluster #DailyCyberSecurity (Aug 19) https://securityonline.info/red-hat-acm-cluster-privilege-escalation/

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑66792, CVSS 9.9) affecting Red Hat ACM is disclosed, describing potential full compromise of managed clusters, with a reference link to more details.

    00000301
    4.9K followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES (CVSS 9.9) CVE-2026-66792: — severity important — Red Hat Security Data (JSON) https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-66792.json #CVE #ZeroDay #PatchManagement

    Post summary

    Red Hat reports CVE‑2026‑66792 with a CVSS score of 9.9, but the post provides no proof‑of‑concept, exploit code, or patch details.

    0000034
    28 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Red Hat Multicluster Global Hub and other products (CVE-2026-66792) https://vuldb.com/vuln/391385

    Post summary

    An advisory for CVE-2026-66792, impacting Red Hat Multicluster Global Hub, has been posted on the vuldb vulnerability database.

    00000111
    2.3K followersView on X

Explore more