PT-2026-70870 · Unknown · Insights-Client
CVE-2026-71475
·
Published
2026-08-11
·
Updated
2026-09-02
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
insights-client (affected versions not specified)
Description
A flaw exists where a compromised managed cluster, known as a spoke, can inject unencoded data into the Insights API URL path. This happens because the
ClusterID variable, which is controlled by the spoke, is used in the request path without proper validation or URL encoding. This allows a malicious spoke to redirect authenticated requests to unintended API endpoints, which could result in unauthorized access or information disclosure.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insights-Client