THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-66792 (CRITICAL 9.9) — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy

[NVD] CVE-2026-66792 (CRITICAL 9.9) — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy

lownvdPublished 2026-08-17

CVE-2026-66792 CVSS: 9.9 CRITICAL Published: 2026-08-17T19:16:34.237

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated pe

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-66792