VDB

CVE-2026-75886

CVE-2026-75886 PUBLISHED CVSS 7.2 HIGH

Reported by redhat · Published September 23, 2026

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the disclosure of the internal operator-catalog index and providing a relay into the openshift-catalogd namespace.

Risk Scores

CVSS 3.1
7.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4.171789939565
Red HatRed Hat OpenShift Container Platform 4.181789904865
Red HatRed Hat OpenShift Container Platform 4.191790095950
Red HatRed Hat OpenShift Container Platform 4.201790112153
Red HatRed Hat OpenShift Container Platform 4.211790142788
Red HatRed Hat OpenShift Container Platform 4.221790130905
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.191790095950, 1790095950
Red HatRed Hat OpenShift Container Platform 4.171789939565
Red HatRed Hat OpenShift Container Platform 4.211790142788, 1790142788, 1790142788
Red HatRed Hat OpenShift Container Platform 4.221790130905, 1790130905, 1790130905
Red HatRed Hat OpenShift Container Platform 4.181789904865
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.201790112153, 1790112153, 1790112153
Red HatRed Hat OpenShift Container Platform 4

Timeline

  • Sep 23, 2026 Coalition ESS Score
  • Sep 23, 2026 CVE Published
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 1, 2026 EPSS Score
  • Oct 1, 2026 CVE Updated
  • Oct 2, 2026 EPSS Score
  • Oct 2, 2026 Distribution Patch
  • Oct 2, 2026 Distribution Patch
  • Oct 2, 2026 Distribution Patch
  • Oct 2, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›