Access Control Vulnerability in Pacemaker Configuration System by Red Hat
CVE-2026-84828
6.5MEDIUM
What is CVE-2026-84828?
A significant flaw in the Pacemaker Configuration System allows local attackers who are part of the 'haclient' group to exploit the 'pcs host auth --token' command. This vulnerability can lead to the unauthorized reading of arbitrary files on the filesystem, specifically those shorter than 256 bytes. The contents of these files are accessed with root privileges via the pcsd daemon, enabling attackers to exfiltrate sensitive data such as API keys and configuration secrets through communication among cluster nodes. This breach poses a considerable risk to the integrity and confidentiality of sensitive information.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Peter Romancik (Red Hat) as the original reporter.