CVE-2026-71845
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Base score: 7.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.50%
- Percentile among all scored CVEs: 41
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement75 % - Primary impact
T1552.001Credentials In Filescredential access85 % - Secondary impact
T1078.002Domain Accountsstealth · persistence · privilege escalation · initial access70 %
CVE-2026-71845: AV:N/PR:L/S:C permite T1210 (servicios remotos requieren privilegios de red). T1552.001 (credenciales en logs) y T1078.002 (uso de token CCX_TOKEN para acceso API no autorizado).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (2)
CWEs
- CWE-532
References
- https://access.redhat.com/errata/RHSA-2026:60386
- https://access.redhat.com/errata/RHSA-2026:60387
- https://access.redhat.com/errata/RHSA-2026:60388
- https://access.redhat.com/errata/RHSA-2026:60389
- https://access.redhat.com/errata/RHSA-2026:60390
- https://access.redhat.com/errata/RHSA-2026:60391
- https://access.redhat.com/security/cve/CVE-2026-71845
- https://bugzilla.redhat.com/show_bug.cgi?id=2512568
Raw JSON (NVD)
Show
{
"id": "CVE-2026-71845",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-71845",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-12T15:27:38.819410Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:acm:2.11::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
"versions": [
{
"status": "unaffected",
"version": "1787688993",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhacm2/insights-client-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:acm:2.13::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
"versions": [
{
"status": "unaffected",
"version": "1787259125",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhacm2/insights-client-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:acm:2.14::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Advanced Cluster Management for Kubernetes 2.14",
"versions": [
{
"status": "unaffected",
"version": "1786882244",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhacm2/insights-client-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:acm:2.15::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Advanced Cluster Management for Kubernetes 2.15",
"versions": [
{
"status": "unaffected",
"version": "1787238585",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhacm2/insights-client-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:acm:2.16::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Advanced Cluster Management for Kubernetes 2.16",
"versions": [
{
"status": "unaffected",
"version": "1787184541",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhacm2/insights-client-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:acm:2.17::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Advanced Cluster Management for Kubernetes 2.17",
"versions": [
{
"status": "unaffected",
"version": "1787227689",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhacm2/insights-client-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-11T20:18:45.800",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2026:60386",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:60387",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:60388",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:60389",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:60390",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:60391",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-71845",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2512568",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API."
}
],
"lastModified": "2026-09-05T18:17:28.487",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B0E6B4B-BAA6-474E-A18C-72C9719CEC1F"
},
{
"criteria": "cpe:2.3:a:redhat:insights-client:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79FB6214-FF6C-49E3-9F87-BD9E2B0A18C7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}