Bug 2507524 (CVE-2026-66780) - CVE-2026-66780 submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace
Summary: CVE-2026-66780 submariner-operator: submariner-operator: flat broker trust mo...
Keywords:
Status: NEW
Alias: CVE-2026-66780
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-27 15:43 UTC by OSIDB Bzimport
Modified: 2026-08-18 16:52 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-27 15:43:48 UTC
The submariner-k8s-broker-cluster Role — bound to the SA token distributed to every joined cluster — grants create,get,list,watch,patch,update,delete on submariner.io/clusters and submariner.io/endpoints across the entire broker namespace with no resourceNames restriction. Each cluster's gateway publishes an Endpoint CR containing its public IP, NAT IP, subnets, and cable-driver parameters; peer gateways read these to establish tunnels.

A compromised spoke can therefore overwrite any other spoke's Endpoint CR to redirect tunnel traffic through an attacker-controlled IP, enabling IPsec MITM across the entire cluster mesh.

Source: Project Glasswing AI-SAST audit of submariner-io/submariner-operator.
Finding ID: FIND-001
Assurance: machine_verified (static analysis + code-level execution proof)


Note You need to log in before you can comment on or make changes to this bug.