Access Control Vulnerability in Pacemaker Configuration System by Red Hat
CVE-2026-84828

6.5MEDIUM

What is CVE-2026-84828?

A significant flaw in the Pacemaker Configuration System allows local attackers who are part of the 'haclient' group to exploit the 'pcs host auth --token' command. This vulnerability can lead to the unauthorized reading of arbitrary files on the filesystem, specifically those shorter than 256 bytes. The contents of these files are accessed with root privileges via the pcsd daemon, enabling attackers to exfiltrate sensitive data such as API keys and configuration secrets through communication among cluster nodes. This breach poses a considerable risk to the integrity and confidentiality of sensitive information.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Peter Romancik (Red Hat) as the original reporter.
.