SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-71475

A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path.

MEDIUM 6.8EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a malicious spoke to redirect authenticated requests to unintended API endpoints, potentially leading to information disclosure or unauthorized access.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
redhat/advanced cluster management for kubernetes · redhat/insights-client
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.