Description
A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.
Published: 2026-09-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

If Submariner certificate-based IPsec authentication mode is enabled (`IPSecCertAuthMode: true` in the SubmarinerConfig), administrators can mitigate this flaw by switching to the default pre-shared key (PSK) authentication mode. Set `IPSecCertAuthMode: false` (or remove the field to use its default value) in the SubmarinerConfig CR and redeploy the Submariner gateway pods. PSK mode provides equivalent inter-cluster IPsec tunnel encryption and is not affected by this vulnerability. Note that disabling cert-auth mode means Submariner will no longer integrate with OVN IPsec's certificate infrastructure and will manage its own PSK-based authentication independently.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.17::el9
References

Wed, 02 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets
First Time appeared Redhat
Redhat acm
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Submariner
Submariner submariner
Vendors & Products Submariner
Submariner submariner

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.
Title submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets
Weaknesses CWE-94
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-03T04:41:49.247Z

Reserved: 2026-07-27T17:51:24.885Z

Link: CVE-2026-66786

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T18:21:10.517

Modified: 2026-09-03T13:06:00.930

Link: CVE-2026-66786

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-21T16:43:00Z

Links: CVE-2026-66786 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:09:52Z

Weaknesses