THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-66794 (CRITICAL 9.3) — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the at

[NVD] CVE-2026-66794 (CRITICAL 9.3) — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the at

mednvdPublished 2026-08-19

CVE-2026-66794 CVSS: 9.3 CRITICAL Published: 2026-08-19T18:17:16.547

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services ac

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-66794