Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66808

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

A flaw was found in hypershift-addon-operator. A hub-cluster administrator with write access to the hypershift-operator-install-flags ConfigMap can inject malicious command-line arguments into the privileged install Job. This vulnerability, known as argument injection, allows the attacker to pull arbitrary container images and gain full administrative control (cluster-admin code execution) on managed spoke clusters.

Отчет

This Important flaw in Multicluster Engine for Kubernetes allows a hub-cluster namespace administrator with write access to the hypershift-operator-install-flags ConfigMap to inject arbitrary command-line arguments into a privileged install Job. This enables privilege escalation to cluster-admin on managed spoke clusters, bypassing security boundaries within the multi-cluster environment.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2509774hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

EPSS

Процентиль: 78%
0.01906
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
13 дней назад

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS3: 8.8
msrc
14 дней назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
github
13 дней назад

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

EPSS

Процентиль: 78%
0.01906
Низкий

8.7 High

CVSS3