---
id: CVE-2026-66786
title: A flaw was found in submariner
summary: >-
  A flaw was found in submariner. In cert-auth mode, the connection
  configuration is built using free-form strings from the Custom Resource
  Definition (CRD) without proper validation. A malicious cluster can exploit
  this by publishing a Ca…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2026-09-02'
updated: '2026-09-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66786'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:63016'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-66786'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507531'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00737
epssPercentile: 0.53068
ingestedAt: '2026-09-05T20:44:35.324Z'
---

## Overview

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
