CVE-2026-66794Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-20); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-08-20: 2Mentions · 2026-08-21: 2Mentions · 2026-08-28: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 2Technical Details · 2026-08-28: 108-2008-2108-28
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-202
Disclosure1Patch1
2026-08-212
Disclosure2
2026-08-281
Patch1
Full discourse5 posts
  • elhacker.NET@elhackernet
    Disclosure

    Fallo crítico de SSRF en Kubernetes de Red Hat expone servicios internos Red Hat ha revelado la vulnerabilidad CVE-2026-66794 , un fallo de Server-Side Request Forgery (SSRF) de severidad alta https://blog.elhacker.net/2026/08/fallo-critico-de-ssrf-en-kubernetes-de.html

    Post summary

    Red Hat announced the high‑severity SSRF vulnerability CVE‑2026‑66794 affecting Kubernetes, providing basic technical details but no PoC, exploit, or mitigation information.

    010047135.6K
    142.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Red Hat Kubernetes の SSRF 脆弱性 CVE-2026-66794:内部サービスへの到達の恐れ https://iototsecnews.jp/2026/08/20/critical-red-hat-kubernetes-ssrf-flaw-exposes-internal-services-across-managed-clusters/ Multicluster Engine for Kubernetes のプロキシ機能に存在する、SSRF の脆弱性 CVE-2026-66794 の動向と対策を解説する記事です。アクセス経路での認証不備および要求転送の検証不足がこの件の背景です。この不備により、内部サービスの無断閲覧/重要データの流出/クラスター内部への不正侵入といった影響が生じる恐れがあります。対応策として、プロキシ用ルートのネットワークアクセス制限/ログによる不審な接続の検知/到達可能な内部機能のセキュリティ再検証が求められます。 #CVE202666794 #Kubernetes #RedHat #Vulnerability

    Post summary

    The article reports on the SSRF flaw CVE‑2026‑66794 in Red Hat Kubernetes’s Multicluster Engine, outlining its potential impact and recommending network‑level restrictions and monitoring as mitigations.

    00000151
    511 followersView on X
  • キタきつね@foxbook
    Disclosure

    Red Hat ACMに最大CVSS 9.9の深刻な権限昇格の脆弱性(CVE-2026-70496等)が発覚 CVE-2026-70496 & CVE-2026-66794: Privilege Escalation in Red Hat ACM Hits CVSS 9.9 #DailyCyberSecurity (Aug 20) https://securityonline.info/red-hat-acm-cve-2026-70496/

    Post summary

    Red Hat ACM was reported to have a severe (CVSS 9.9) privilege escalation vulnerability identified as CVE-2026-70496 and CVE-2026-66794, with no evidence of PoC, exploit code, or patches provided in this text.

    00000301
    4.9K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Red Hat’s Multicluster Engine for Kubernetes is battling a high-severity SSRF bug (CVE-2026-66794) in its cluster-proxy-addon that lets unauthenticated attackers access internal services across managed clusters. With a CVSS score of 9.3 but rated only "Important," the flaw exploits a route lacking tighter auth and segmentation. If your systems use <em>cluster-proxy-addon-rhel9</em>, lock that endpoint down now and audit exposed paths. #Kubernetes #RedHat #SSRF #Multicluster #CloudSecurity #Vulnerability #Kubernetes #RedHat #SSRF #CloudSecurity #Multicluster #Vulnerability #Cybersecurity https://thedailytechfeed.com/critical-ssrf-in-red-hats-kubernetes-multicluster-engine-leaves-internal-services-exposed/

    Post summary

    The tweet alerts users to a high‑severity SSRF flaw in Red Hat's Multicluster Engine and urges them to harden the exposed endpoint and audit paths as a mitigation step.

    0000039
    652 followersView on X
  • Undercode News@undercode_news
    Disclosure

    🚨 #Red Hat #Kubernetes SSRF Vulnerability #CVE-2026-66794: A Hidden Proxy Route Could Open the Door to Isolated Cluster Services + Video -Fact Checker: ✅: 3 ❌: 0 || 3/3 → Score: 100% 🦾 -Prediction: 📈 3 Positive | 📉 2 Negative https://undercodenews.com/red-hat-kubernetes-ssrf-vulnerability-cve-2026-66794-a-hidden-proxy-route-could-open-the-door-to-isolated-cluster-services-video/

    Post summary

    This post announces the new #CVE-2026-66794 SSRF vulnerability in Red Hat Kubernetes, highlighting a hidden proxy route that could expose isolated cluster services, and directs readers to a video for more details.

    0000020
    92 followersView on X

Explore more