THREAT OPS › Threat News › [NVD] CVE-2026-66794 (CRITICAL 9.3) — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the at
[NVD] CVE-2026-66794 (CRITICAL 9.3) — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the at
CVE-2026-66794 CVSS: 9.3 CRITICAL Published: 2026-08-19T18:17:16.547
A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services ac
Indicators of compromise
- CVE-2026-66794cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-66794