ThreatCluster

Red Hat Kubernetes SSRF Vulnerability Exposes Internal Services to Attackers

First seen 21 Aug 2026, 02:22 UTC GbhackersCybersecuritynews 96% similarity 69

Article Content

Browse articles
ThreatCluster

Red Hat disclosed CVE-2026-66794, a high-severity SSRF vulnerability in the cluster-proxy-addon of the Multicluster Engine for Kubernetes. This flaw, rated with a CVSS v3.1 score of 9.3, allows unauthenticated remote attackers to access internal services across managed Kubernetes clusters via a publicly accessible route. The vulnerability affects users of Red Hat's Kubernetes offerings, potentially exposing sensitive internal services. The issue was published on August 19, 2026, and has raised significant concerns due to its potential for exploitation. Organizations using affected systems are advised to assess their security posture and apply necessary mitigations.

Key Points: • CVE-2026-66794 is a high-severity SSRF vulnerability with a CVSS score of 9.3. • The flaw allows unauthenticated attackers to access internal services across managed Kubernetes clusters. • Red Hat published details of the vulnerability on August 19, 2026.

ThreatCluster AI How this analysis works

Timeline

2026-08-19
CVE-2026-66794 published
Red Hat disclosed a high-severity SSRF vulnerability in the cluster-proxy-addon of the Multicluster Engine for Kubernetes.
Cybersecuritynews
2026-08-20
Vulnerability details reported
Both Cybersecuritynews and Gbhackers reported on the SSRF vulnerability affecting Kubernetes clusters.
Gbhackers

Community

Browse all →

Tracked Entities in This Story