cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in rest…

cve CVE-2026-66798 2 sources, 2 claims · Watch

Red Hat writes:
cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods the claim
Severity they disagree
MEDIUM NVD
important Red Hat
CVSS they disagree
4.3 NVD
8.8 Red Hat
Fixed in
152.0.4191.52 NVD
Vendor
Microsoft NVD
Product
Microsoft Edge (Chromium-based) NVD
CWE
CWE-416 NVD
CWE-77 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nnetwork N
Attack complexity AClow Llow L
Privileges required PRnone Nlow L
User interaction UIrequired Rnone N
Scope Sunchanged Uunchanged U
Confidentiality Cnone Nhigh H
Integrity Inone Nhigh H
Availability Alow Lhigh H

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-08-11first spoke of it: cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored podsRed Hat
2026-08-28first spoke of it: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.NVD

cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods

What it is to other things

affectsmicrosoft/edge_chromium
NVD
made_bymicrosoft
NVD

In words only, so not counted until a person confirms one:

affectsmicrosoft/microsoft_edge_chromium_based
NVD says “Microsoft · Microsoft Edge (Chromium-based)”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD4.3
receipt
Source
NVD
Its words
4.3
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat8.8
receipt
Source
Red Hat
Its words
8.8
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-66798",
  "CWE": "CWE-77",
  "advisories": [
    "RHSA-2026:60391",
    "RHSA-2026:60390",
    "RHSA-2026:60386",
    "RHSA-2026:60389",
    "RHSA-2026:60388",
    "RHSA-2026:60387"
  ],
  "affected_packages": [
    "rhacm2/cluster-backup-rhel9-operator:1787684668",
    "rhacm2/cluster-backup-rhel9-operator:1787238500",
    "rhacm2/cluster-backup-rhel9-operator:1787227576",
    "rhacm2/cluster-backup-rhel9-operator:1787183178",
    "rhacm2/cluster-backup-rhel9-operator:1787183176",
    "rhacm2/cluster-backup-rhel9-operator:1787259060"
  ],
  "bugzilla": "2507993",
  "bugzilla_description": "cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-66798.json",
  "severity": "important"
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-66798",
  "CWE": "CWE-77",
  "advisories": [
    "RHSA-2026:60391",
    "RHSA-2026:60390",
    "RHSA-2026:60386",
    "RHSA-2026:60389",
    "RHSA-2026:60388",
    "RHSA-2026:60387"
  ],
  "affected_packages": [
    "rhacm2/cluster-backup-rhel9-operator:1787684668",
    "rhacm2/cluster-backup-rhel9-operator:1787238500",
    "rhacm2/cluster-backup-rhel9-operator:1787227576",
    "rhacm2/cluster-backup-rhel9-operator:1787183178",
    "rhacm2/cluster-backup-rhel9-operator:1787183176",
    "rhacm2/cluster-backup-rhel9-operator:1787259060"
  ],
  "bugzilla": "2507993",
  "bugzilla_description": "cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-66798.json",
  "severity": "important"
}
—
CWE
cwe
different words
NVDCWE-416
receipt
Source
NVD
Its words
CWE-416
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-416
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-77
receipt
Source
Red Hat
Its words
CWE-77
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-66798",
  "CWE": "CWE-77",
  "advisories": [
    "RHSA-2026:60391",
    "RHSA-2026:60390",
    "RHSA-2026:60386",
    "RHSA-2026:60389",
    "RHSA-2026:60388",
    "RHSA-2026:60387"
  ],
  "affected_packages": [
    "rhacm2/cluster-backup-rhel9-operator:1787684668",
    "rhacm2/cluster-backup-rhel9-operator:1787238500",
    "rhacm2/cluster-backup-rhel9-operator:1787227576",
    "rhacm2/cluster-backup-rhel9-operator:1787183178",
    "rhacm2/cluster-backup-rhel9-operator:1787183176",
    "rhacm2/cluster-backup-rhel9-operator:1787259060"
  ],
  "bugzilla": "2507993",
  "bugzilla_description": "cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-66798.json",
  "severity": "important"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Fixed in
fixed_in
NVD152.0.4191.52
receipt
Source
NVD
Its words
152.0.4191.52
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTC152.0.4191.52
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Packages
packages
Red Hatrhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787183176, rhacm2/cluster-backup-rhel9-operator:1787259060
receipt
Source
Red Hat
Its words
rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787183176, rhacm2/cluster-backup-rhel9-operator:1787259060
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-66798",
  "CWE": "CWE-77",
  "advisories": [
    "RHSA-2026:60391",
    "RHSA-2026:60390",
    "RHSA-2026:60386",
    "RHSA-2026:60389",
    "RHSA-2026:60388",
    "RHSA-2026:60387"
  ],
  "affected_packages": [
    "rhacm2/cluster-backup-rhel9-operator:1787684668",
    "rhacm2/cluster-backup-rhel9-operator:1787238500",
    "rhacm2/cluster-backup-rhel9-operator:1787227576",
    "rhacm2/cluster-backup-rhel9-operator:1787183178",
    "rhacm2/cluster-backup-rhel9-operator:1787183176",
    "rhacm2/cluster-backup-rhel9-operator:1787259060"
  ],
  "bugzilla": "2507993",
  "bugzilla_description": "cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-66798.json",
  "severity": "important"
}
—
Product
product
NVDMicrosoft Edge (Chromium-based)
receipt
Source
NVD
Its words
Microsoft Edge (Chromium-based)
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCMicrosoft Edge (Chromium-based)
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Severity
severity
conflict
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-66798",
  "CWE": "CWE-77",
  "advisories": [
    "RHSA-2026:60391",
    "RHSA-2026:60390",
    "RHSA-2026:60386",
    "RHSA-2026:60389",
    "RHSA-2026:60388",
    "RHSA-2026:60387"
  ],
  "affected_packages": [
    "rhacm2/cluster-backup-rhel9-operator:1787684668",
    "rhacm2/cluster-backup-rhel9-operator:1787238500",
    "rhacm2/cluster-backup-rhel9-operator:1787227576",
    "rhacm2/cluster-backup-rhel9-operator:1787183178",
    "rhacm2/cluster-backup-rhel9-operator:1787183176",
    "rhacm2/cluster-backup-rhel9-operator:1787259060"
  ],
  "bugzilla": "2507993",
  "bugzilla_description": "cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods",
  "cvss3_score": "8.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-08-11T00:00:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-66798.json",
  "severity": "important"
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDMicrosoft
receipt
Source
NVD
Its words
Microsoft
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCMicrosoft
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Microsoft Edge (Chromium-based)",
            "vendor": "Microsoft",
            "versions": [
              {
                "status": "affected",
                "version": "-"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Android",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for iOS",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Linux",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for MAC",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Microsoft Edge for Windows",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "152.0.4191.52",
                "status": "affected",
                "version": "1.0.0.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6E9AEFC6-9482-4267-97E5-03E734356F37",
                "versionEndExcluding": "152.0.4191.53",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."
      }
    ],
    "id": "CVE-2026-66798",
    "lastModified": "2026-09-11T17:17:43.290",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 1.4,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-66798",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-29T03:56:13.736994Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-28T20:19:34.673",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods
zetlyn/cve-redhat · 2026-08-11
cvss 8.8 cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cwe CWE-77 packages rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787183176, rhacm2/cluster-backup-rhel9-operator:1787259060 severity important source
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
zetlyn/cve-nvd · 2026-08-28
automatable no cvss 4.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L cwe CWE-416 exploitation none fixed_in 152.0.4191.52 product Microsoft Edge (Chromium-based) severity MEDIUM status Analyzed technical_impact total vendor Microsoft source