CVE-2026-66788
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namesp
CVSS
9.9
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 20, 2026 · Last modified: Aug 20, 2026 · CWE-284
Not enough EPSS history yet.
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.