Information Disclosure Vulnerability in Red Hat Insights Client
CVE-2026-71474

6.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-71474?

An information disclosure vulnerability exists within the Red Hat Insights Client when it encounters a non-200 HTTP response. The application logs the request headers, which may unintentionally include sensitive information such as the pull-secret token from cloud.openshift.com. If a local user gains access to the pod logs on the hub, they can potentially read this long-lived credential, leading to unauthorized access to Red Hat cloud services. It is essential for users and administrators to be aware of this vulnerability and to ensure that proper security measures are in place to mitigate any risks.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.