Environment Variable Logging Vulnerability in Insights Client by Red Hat
CVE-2026-71845

6.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
11 August 2026

What is CVE-2026-71845?

A security flaw has been identified in the Insights Client where the setDefault() function logs all processed environment variables, including sensitive information like the CCX_TOKEN. This token is a bearer credential critical for operating in disconnected cluster deployments. When the glog verbosity level is increased to 2 or higher, the CCX_TOKEN is recorded in plain text in the pod logs each time the application starts. If an attacker gains access to these logs or the centralized logging system, they could exploit this vulnerability to obtain the credential, resulting in unauthorized access to the CCX API.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.