HIGHVulnerability

CVE-2026-66878

A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.

Properties

severity
HIGH
score
7.7
cve_id
CVE-2026-66878
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
published_at
2026-08-12T02:16:37.937
last_modified
2026-08-26T22:16:27.017

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66878 — Ninja Signal Threat Intelligence | Ninja Signal