CVE-2026-66787CWE-489

CVE-2026-66787

Medium · published August 20, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
15.0
In the wild
Unconfirmed
What it is

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00240 · 15.0th percentile
Weakness
CWE-489 · Active Debug Code
Published
2026-08-20T23:16Z
References (3)
EPSS history
Timeline
  • 20 AUG 18:15Z
    Lighthouse: lighthouse: cross-cluster dns spoofing via unvalidated endpointslice and serviceimport ips
    cvelistv5