What is CVE-2026-66795?
A vulnerability was found in the managedcluster-import-controller's CSR auto-approval logic due to improper validation of incoming CSRs. It fails to inspect the signer name, allowing a privileged service account to potentially exploit spoofed x509 CSRs. Mitigation requires enforcing proper CSR validation.
Azərbaycanca: managedcluster-import-controller-da CSR avtomatik təsdiqləmə məntiqində boşluq aşkarlanıb. Bu zəiflik imzalayan adını yoxlamamaqla saxta x509 CSR-lər vasitəsilə imtiyazlı xidmət hesabına təsir göstərə bilər. Təhlükəsizlik tədbiri kimi CSR-lərin düzgün validasiyası təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What causes the vulnerability in the managedcluster-import-controller?
The vulnerability stems from the CSR auto-approval logic failing to inspect the signer name.
How can this vulnerability be exploited?
A privileged service account can exploit it using spoofed x509 CSRs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.