What is CVE-2026-66782?
A critical flaw was found in the Submariner operator, exposing a long-lived broker Service Account (SA) token within the Custom Resource (CR) specification. An attacker with access to the etcd database or 'kubectl get' commands could obtain this token. Updating to the latest version of the operator is recommended.
Azərbaycanca: Submariner operator-da kritik bir boşluq aşkarlanıb, burada uzunömürlü broker xidmət hesabı (Service Account) tokeni Custom Resource (CR) spesifikasiyası daxilində açıq qalır. etcd verilənlər bazasına və ya 'kubectl get' əmrlərinə girişi olan hücumçu bu tokeni əldə edə bilər. Operatorun ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What is the CVE-2026-66782 vulnerability found in the Submariner operator?
CVE-2026-66782 is a critical flaw in the Submariner operator where a long-lived broker Service Account (SA) token is exposed within the Custom Resource (CR) specification.
How can the CVE-2026-66782 vulnerability be exploited?
An attacker with access to the etcd database or 'kubectl get' commands could obtain the exposed token.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.