What is CVE-2026-66792?
A critical flaw was found in the multicloud-operators-subscription component (CVE-2026-66792). A user on a managed cluster can escalate their privileges by creating a Subscription with crafted annotations. Successful exploitation allows the attacker to deploy resources into any cluster.
Azərbaycanca: multicloud-operators-subscription komponentində kritik bir boşluq aşkarlanıb (CVE-2026-66792). İdarə olunan klasterdəki istifadəçi xüsusi hazırlanmış annotasiyalarla Subscription yaradaraq imtiyazlarını yüksəldə bilər. Bu zəiflik uğurlu istismar edildikdə, hücumçuya istənilən klasterə resurs yerləşdirmək imkanı verir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which component is affected by CVE-2026-66792?
This vulnerability was found in the multicloud-operators-subscription component.
How can an attacker exploit CVE-2026-66792?
A user on a managed cluster can escalate their privileges by creating a Subscription with crafted annotations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.