MEDIUMVulnerability

CVE-2026-66782

A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl get` commands could obtain this token. The possession of this token grants full control over the mesh network, enabling unauthorized management of network resources such as endpoints and secrets.

Properties

severity
MEDIUM
score
5.8
epss_score
0.0028
cve_id
CVE-2026-66782
vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
published_at
2026-08-18T17:17:00.710
last_modified
2026-09-03T13:06:00.497
epss_percentile
0.20083

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66782 — Ninja Signal Threat Intelligence | Ninja Signal