Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters

Red Hat has disclosed CVE-2026-66794, a high-severity Server-Side Request Forgery vulnerability affecting the cluster-proxy-addon component in Multicluster Engine for Kubernetes. The issue carries a CVSS v3.1 score of 9.3. It could allow unauthenticated remote attackers to reach otherwise inaccessible services running across managed Kubernetes clusters. The vulnerability exists in a user-facing route exposed by the […]

This article has been indexed from Cyber Security News

Read the original article: