CVE-2026-66795
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates inc
CVSS
9.9
Critical
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Published: Aug 17, 2026 · Last modified: Sep 8, 2026 · CWE-295
0.2%EPSS · 30 days0.4%
2026-08-182026-09-11
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59556
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59557
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59558
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59559
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59579
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59593
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-66795
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2507540
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-906518.1 HIG—
———Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts any certificate, including self-signed and otherwise untrusted certificates, without validating the chain. An attacker positioned to intercept traffic between Socket Firewall and the Socket API or an upstream package registry can present a crafted certificate and modify responses in transit, including substituting malicious package content or altering the allow/block decisions the firewall enforces. Setting api_ssl_verify: true and upstream_ssl_verify: true enables verification; however, in versions before 1.1.334, the generated nginx configuration did not emit lua_ssl_trusted_certificate, and thus verification could not be used successfully without manually patching the generated configuration. Version 2.0.0 changes the default for both settings to true.2hCVE-2026-906477.4 HIG—
———ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.3hCVE-2026-90452——
——0Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.1dCVE-2026-878726.8 MED0.5%
——0A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the
community.general Ansible collection. The shared OCAPI request helper disables
TLS certificate validation on every request and the modules expose no parameter
to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint.
An attacker positioned on the network path between the Ansible controller and the
OCAPI-managed storage/enclosure device can present any certificate, intercept the
session, capture the credentials, and tamper with responses.3dCVE-2026-797363.7 LOW2.4%
——1Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.3dCVE-2026-797323.7 LOW1.5%
——0Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.3d