A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 21:16
Updated : 2026-09-08 13:17
NVD link : CVE-2026-66795
Mitre link : CVE-2026-66795
CVE.ORG link : CVE-2026-66795
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
