Local Vulnerability in cockpit-machines Exposing Sensitive Red Hat Tokens
CVE-2026-92745

5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 September 2026

What is CVE-2026-92745?

A vulnerability exists in the cockpit-machines component that permits local attackers to view process metadata, which can expose sensitive Red Hat Subscription Management (RHSM) offline tokens. The tokens are inadvertently included as command-line arguments during their validation, making them accessible to unauthorized users. Successful exploitation of this flaw can lead to potential confidentiality breaches, enabling attackers to utilize the exposed tokens to gain unauthorized access to additional resources.

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.