Crypto Ticker:
sysadmin from Cyber Security News

Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters

Abinaya
4 hours ago
23 Views
0 Comments
Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters

Red Hat has disclosed CVE-2026-66794, a high-severity Server-Side Request Forgery vulnerability affecting the cluster-proxy-addon component in Multicluster Engine for Kubernetes. The issue carries a CVSS v3.1 score of 9.3. It could allow unauthenticated remote attackers to reach otherwise inaccessible services running across managed Kubernetes clusters. The vulnerability exists in a user-facing route exposed by the cluster proxy add-on. According to Red Hat, the route does not properly enforce authentication and authorization before forwarding requests. An attacker who can access this endpoint can manipulate URL path segments to make the proxy send requests to arbitrary services in managed clusters. This behavior is classified...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!