Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66800

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

A flaw was found in cluster-backup-operator. A namespace administrator with privileges in the open-cluster-management-backup namespace can exploit a feature in the Restore Custom Resource (CR). By setting the cleanupBeforeRestore field to CleanupAll, an attacker can trigger an unguarded, cluster-wide deletion of all Red Hat Advanced Cluster Management (ACM) and Hive-labelled Secrets and ConfigMaps. This leads to a denial of service across the entire hub cluster by removing critical resources.

Отчет

This vulnerability is rated as Important. A namespace administrator within the open-cluster-management-backup namespace in Red Hat Advanced Cluster Management for Kubernetes can initiate a cluster-wide denial of service. This occurs by leveraging the cleanupBeforeRestore: CleanupAll option in a Restore Custom Resource, which causes the cluster-backup-operator to delete all ACM/Hive-labelled Secrets and ConfigMaps across the hub cluster, regardless of their restore labels.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2507995cluster-backup-operator: cluster-backup-operator: CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount

EPSS

Процентиль: 44%
0.0054
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 месяца назад

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

msrc
около 1 месяца назад

Azure Data Factory Information Disclosure Vulnerability

CVSS3: 8.6
github
около 1 месяца назад

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

EPSS

Процентиль: 44%
0.0054
Низкий

7.1 High

CVSS3