AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66016

MEDIUM · CVSS 6.7 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Certain self-hosted Helm configurations may inadvertently expose generated TLS private keys in rendered manifests, allowing highly privileged local users to access sensitive information. This vulnerability could lead to unauthorized access to secure communications and data breaches. Organizations utilizing Helm for container orchestration should prioritize addressing this issue to mitigate potential risks associated with key exposure.

CVE
CVE-2026-66016
Severity
MEDIUM
CVSS
6.7
EPSS
0.08%

Original NVD Description

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.