Data Injection Vulnerability in Insights Client by Red Hat
CVE-2026-71475

5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-71475?

A vulnerability exists in the Insights Client where a compromised managed cluster, known as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs when the ClusterID, which is under the control of the spoke, is included in the request path without appropriate validation or URL encoding. As a result, this flaw can enable a malicious spoke to redirect authenticated requests to unintended API endpoints. This redirection could lead to potential information disclosure or unauthorized access, posing significant risks to users and their data.

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.