PT-2026-70870 · Unknown · Insights-Client

CVE-2026-71475

·

Published

2026-08-11

·

Updated

2026-09-02

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions insights-client (affected versions not specified)
Description A flaw exists where a compromised managed cluster, known as a spoke, can inject unencoded data into the Insights API URL path. This happens because the ClusterID variable, which is controlled by the spoke, is used in the request path without proper validation or URL encoding. This allows a malicious spoke to redirect authenticated requests to unintended API endpoints, which could result in unauthorized access or information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71475

Affected Products

Insights-Client