A critical vulnerability (CVE-2026-66788) was discovered in Lighthouse, a component used in multi-cluster Kubernetes/OpenShift environments. A remote attacker who has compromised a spoke cluster can exploit this flaw by manipulating attacker-controlled labels or annotations on broker objects to control the destination namespace for resource injection. This allows unauthorized injection of EndpointSlices and ServiceImports into any namespace on peer clusters, including sensitive system namespaces such as kube-system and openshift-*. The vulnerability can lead to privilege escalation and broader system compromise across connected clusters. The flaw is documented by Red Hat and tracked via Bugzilla issue 2507533. It represents a significant risk in federated or multi-cluster Kubernetes deployments. The attack vector is remote and requires an initial foothold on a spoke cluster. Organizations using Lighthouse in Submariner or similar multi-cluster service discovery setups are at risk.