Red Hat Kubernetes SSRF Vulnerability Exposes Internal Services to Attackers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
Red Hat disclosed CVE-2026-66794, a high-severity SSRF vulnerability in the cluster-proxy-addon of the Multicluster Engine for Kubernetes. This flaw, rated with a CVSS v3.1 score of 9.3, allows unauthenticated remote attackers to access internal services across managed Kubernetes clusters via a publicly accessible route. The vulnerability affects users of Red Hat's Kubernetes offerings, potentially exposing sensitive internal services. The issue was published on August 19, 2026, and has raised significant concerns due to its potential for exploitation. Organizations using affected systems are advised to assess their security posture and apply necessary mitigations.
Key Points: • CVE-2026-66794 is a high-severity SSRF vulnerability with a CVSS score of 9.3. • The flaw allows unauthenticated attackers to access internal services across managed Kubernetes clusters. • Red Hat published details of the vulnerability on August 19, 2026.