CVE-2026-66795 | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the h
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
- 🔗 access.redhat.com/errata/RHSA-2026:59556
- 🔗 access.redhat.com/errata/RHSA-2026:59557
- 🔗 access.redhat.com/errata/RHSA-2026:59558
- 🔗 access.redhat.com/errata/RHSA-2026:59559
- 🔗 access.redhat.com/errata/RHSA-2026:59579
- 🔗 access.redhat.com/errata/RHSA-2026:59593
- 🔗 access.redhat.com/security/cve/CVE-2026-66795
- 🔗 bugzilla.redhat.com/show_bug.cgi
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-24 | 2026-10-08 |
|---|---|---|
| ≥90 % | 484 | 342 |
| ≥50 % | 1436 | 1061 |
| ≥10 % | 16 | 2 |
| <10 % | 30 | 562 |
CVE-2026-66795 | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the h
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. Thi
Noch keine Analyse zu CVE-2026-66795
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.