PT-2026-70871 · Unknown · Insights-Client

CVE-2026-71845

·

Published

2026-08-11

·

Updated

2026-08-27

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions insights-client (affected versions not specified)
Description A flaw exists in the setDefault() function that logs the value of every environment variable it processes. This includes CCX TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, this token is written in clear text to the pod log during every startup. An attacker with access to pod logs or centralized logging could obtain this credential to gain unauthorized access to the CCX API.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71845

Affected Products

Insights-Client