What is CVE-2026-66781?
CVE-2026-66781 is a vulnerability found in the Submariner operator. The IPsec pre-shared key (PSK), critical for securing communication between Kubernetes clusters, is stored in an unencrypted format within the Submariner Custom Resource (CR), allowing unauthorized access. Upgrading the operator to the latest patched version is recommended to remediate this issue.
Azərbaycanca: CVE-2026-66781 Submariner operator-da aşkar edilmiş boşluqdur. Kubernetes klasterləri arasında IPsec şifrələməsi üçün kritik olan əvvəlcədən paylaşılmış açar (PSK) Submariner Custom Resource (CR) daxilində şifrələnməmiş formatda saxlanır və icazəsiz şəxslər tərəfindən əldə oluna bilər. Bu problemi aradan qaldırmaq üçün operatoru ən son yenilənmiş versiyaya yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
What secret information is left unprotected in the CVE-2026-66781 vulnerability in the Submariner operator?
This vulnerability relates to the IPsec pre-shared key (PSK) being stored in an unencrypted format within the Submariner Custom Resource (CR).
What action is recommended to remediate the CVE-2026-66781 vulnerability?
It is recommended to upgrade the Submariner operator to the latest patched version to remediate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.