Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66799

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.

A flaw was found in the cluster-backup-operator. A privileged user with administrative access to a specific namespace could exploit a vulnerability in the backup restoration process. This flaw allows them to redirect sensitive information, such as cloud provider credentials and access tokens, from backup operations into other namespaces, including those they control. This could lead to unauthorized access to critical system resources and the disclosure of confidential data.

Отчет

This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. A namespace administrator within the open-cluster-management-backup namespace can exploit the cluster-backup-operator to redirect sensitive credential Secrets and ConfigMaps from backed-up namespaces into any target namespace, including those controlled by the attacker. This allows for a cross-namespace write of credential material, potentially leading to unauthorized access to cloud provider credentials, pull secrets, and ManagedServiceAccount tokens.

Меры по смягчению последствий

To mitigate this issue, restrict administrative access to the open-cluster-management-backup namespace. Only trusted administrators should have permissions to create or modify Restore Custom Resources within this namespace, as this action is required to exploit the vulnerability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2507994cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement

EPSS

Процентиль: 19%
0.00269
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 1 месяца назад

Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
msrc
около 1 месяца назад

Windows Key Guard Elevation of Privilege Vulnerability

CVSS3: 7.8
github
около 1 месяца назад

Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.

EPSS

Процентиль: 19%
0.00269
Низкий

7.1 High

CVSS3