Database/Container, Kubernetes & orchestration
Submariner: IPsec pre-shared key stored unencrypted in the Submariner custom resource
Impact
Submariner's IPsec PSK, which secures every tunnel between clusters in the mesh, is written into the Submariner CR in cleartext rather than a protected secret. Anyone who can read that CR holds the key to the whole mesh and can passively decrypt captured traffic between any two clusters — no active position needed, and captures taken before the key was read decrypt just as well. Where a GPU fleet is split across clusters, that inter-cluster traffic carries scheduler and control-plane calls, dataset and model-artifact transfers, and whatever tenant traffic crosses the mesh. The record scores this with a changed scope, reflecting that a reader in one cluster compromises traffic belonging to others.
Who can reach it
A low-privileged local account with read access to the Submariner CR (AV:L/PR:L in the scored vector) — in practice any service account or user whose RBAC grants get on that resource, which is often broader than intended. Turning the key into plaintext also requires the ability to capture inter-cluster traffic somewhere on the path.
What to do
The record names no fixed version; Red Hat tracks it for Advanced Cluster Management for Kubernetes 2 in bugzilla 2507526, so watch that page and the RHACM errata rather than assuming a build. In the meantime, audit and tighten RBAC so only the Submariner operator's own service account can read the CR, treat the current PSK as compromised, and plan a key rotation — rotation re-establishes the tunnels and briefly interrupts cross-cluster connectivity, so schedule it. No node reboot or firmware work is involved.
References
Related entries
- KubeSphere cluster-controller: Cluster CRD endpoint is fetched unvalidated, giving SSRF from the controller podCVE-2026-71208 · KubeSphere cluster-controller (Cluster CRD connection config, addCluster / Discovery.ServerVersion)Medium
- ECK operator: unvalidated secret reference lets a namespace-scoped user read secrets from any namespaceCVE-2026-72640 · Elastic Cloud on Kubernetes (ECK) operator (secret reference reconciliation)Medium
- Elastic Cloud on Kubernetes: Fleet Server Elasticsearch token written into the workload spec in cleartextCVE-2026-72648 · Elastic Cloud on Kubernetes (ECK) operator - Fleet Server workload specMedium
- Dokploy: compose service names are interpolated into shell commands, giving command execution on the Docker hostCVE-2026-72739 · Dokploy (compose deployment createCommand shell interpolation)Medium
- Rancher Fleet: bundle content can read files from the bundle-processing job and leak Helm registry credentialsCVE-2026-93537 · SUSE Rancher Fleet (GitRepo bundle processing, file read into Bundle resource)Medium
- Kubernetes (kube-apiserver): Unvalidated redirect on proxied upgrade requests lets a compromised node escalate to otherCVE-2020-8559 · Kubernetes (kube-apiserver)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.