{"apiVersion":"1.0","identifier":"CVE-2026-66788","description":"A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.","publishedAt":"2026-08-20T19:16:58","lastModifiedAt":"2026-08-20T19:16:58","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66788","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","epssProbability":0.00293,"riskScore":1.02,"affectedProduct":"Lighthouse","affectedVersions":"unknown","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-66788","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-66788","en":"https://www.redsauce.net/en/cves/CVE-2026-66788","fr":"https://www.redsauce.net/fr/cves/CVE-2026-66788","pt":"https://www.redsauce.net/pt/cves/CVE-2026-66788","de":"https://www.redsauce.net/de/cves/CVE-2026-66788","sk":"https://www.redsauce.net/sk/cves/CVE-2026-66788","el":"https://www.redsauce.net/el/cves/CVE-2026-66788"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-66788"}}