Local Vulnerability in cockpit-machines Exposing Sensitive Red Hat Tokens
CVE-2026-92745
5MEDIUM
What is CVE-2026-92745?
A vulnerability exists in the cockpit-machines component that permits local attackers to view process metadata, which can expose sensitive Red Hat Subscription Management (RHSM) offline tokens. The tokens are inadvertently included as command-line arguments during their validation, making them accessible to unauthorized users. Successful exploitation of this flaw can lead to potential confidentiality breaches, enabling attackers to utilize the exposed tokens to gain unauthorized access to additional resources.
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.