A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-18 15:17
Updated : 2026-08-27 04:16
NVD link : CVE-2026-66793
Mitre link : CVE-2026-66793
CVE.ORG link : CVE-2026-66793
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
