← Back to overview

A critical vulnerability was discovered in Submariner, a Kubernetes multi-cluster networking component. In cert-auth mode, connection configurations are built from unvalidated free-form strings sourced from Custom Resource Definitions (CRDs). A malicious cluster can exploit this by publishing a crafted CableName containing newline characters and arbitrary ipsec.conf directives. This enables injection of unauthorized configuration parameters into the IPsec configuration file. Attackers can further leverage leftupdown hooks to execute arbitrary commands. The end result is remote code execution with root privileges on the gateway node. The vulnerability poses a severe risk in multi-cluster Kubernetes environments using Submariner for secure tunneling.

Affected products

  • Submariner

Related CVE's

  • CVE-2026-66786

Categories

  • Cloud & Virtualization
  • Network Infrastructure