What is CVE-2026-66878?
A flaw was found in multicloud-operators-subscription. A privileged user (namespace administrator) can exploit this by manipulating the Channel.Spec.SecretRef.Namespace field, leading to unauthorized copy of secrets. Applying the relevant software updates is recommended to mitigate this vulnerability.
Azərbaycanca: Bu boşluq 'multicloud-operators-subscription' komponentində aşkarlanıb. İmtiyazlı istifadəçi (namespace administratoru) Channel.Spec.SecretRef.Namespace sahəsini manipulyasiya edərək sistemdə sirrlərin kopyalanmasına səbəb ola bilər. Bu zəifliyi aradan qaldırmaq üçün müvafiq proqram təminatı yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What privileges are required to exploit CVE-2026-66878?
To exploit this vulnerability, the attacker must have privileged user access, specifically namespace administrator privileges.
What mitigation is recommended for CVE-2026-66878?
It is recommended to apply the relevant software updates to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.