Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in cluster-backup-operator. A namespace administrator in open-cluster-management-backup can create a Restore Custom Resource (CR) with malicious hooks. These hooks allow the execution of arbitrary commands within any matching restored pod, leading to the exfiltration of ServiceAccount tokens. This bypasses normal access controls, granting the attacker unauthorized execution access to pods and their associated Service Accounts. | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| Title | cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| First Time appeared |
Microsoft
Microsoft edge Chromium |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft edge Chromium |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 12 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in cluster-backup-operator. A namespace administrator in open-cluster-management-backup can create a Restore Custom Resource (CR) with malicious hooks. These hooks allow the execution of arbitrary commands within any matching restored pod, leading to the exfiltration of ServiceAccount tokens. This bypasses normal access controls, granting the attacker unauthorized execution access to pods and their associated Service Accounts. | |
| Title | cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-29T16:24:59.209Z
Reserved: 2026-07-27T19:02:26.600Z
Link: CVE-2026-66798
Updated: 2026-08-28T20:33:06.439Z
Status : Received
Published: 2026-08-28T20:19:34.673
Modified: 2026-08-29T04:18:05.970
Link: CVE-2026-66798
OpenCVE Enrichment
Updated: 2026-08-28T21:30:05Z