Data Injection Vulnerability in Insights Client by Red Hat
CVE-2026-71475
5MEDIUM
What is CVE-2026-71475?
A vulnerability exists in the Insights Client where a compromised managed cluster, known as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs when the ClusterID, which is under the control of the spoke, is included in the request path without appropriate validation or URL encoding. As a result, this flaw can enable a malicious spoke to redirect authenticated requests to unintended API endpoints. This redirection could lead to potential information disclosure or unauthorized access, posing significant risks to users and their data.