Remote Authentication Bypass in OpenShift Console by Red Hat
CVE-2026-75886

7.2HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-75886?

A misconfiguration in the OpenShift Console can be exploited by unauthenticated remote attackers. This flaw arises due to insufficient authentication checks in the CatalogdHandler, allowing attackers to manipulate requests to the in-cluster catalogd service. By exploiting this weakness, an attacker could gain access to sensitive data, including the internal operator-catalog index and related information, thereby compromising the security of the OpenShift environment.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.