MEDIUMVulnerability

CVE-2026-66781

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure.

Properties

severity
MEDIUM
score
5.4
epss_score
0.00264
cve_id
CVE-2026-66781
vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
published_at
2026-08-18T17:17:00.580
last_modified
2026-09-03T13:06:00.327
epss_percentile
0.17998

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Exposed Dangerous Method or Function

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66781 — Ninja Signal Threat Intelligence | Ninja Signal