VDB
CVE-2026-75886
CVE-2026-75886
PUBLISHED
CVSS 7.2 HIGH
Reported by redhat · Published September 23, 2026
A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker to send requests to the in-cluster catalogd service, leading to the disclosure of the internal operator-catalog index and providing a relay into the openshift-catalogd namespace.
Risk Scores
CVSS 3.1
7.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1789939565 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1789904865 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790095950 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790112153 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790142788 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790130905 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790095950, 1790095950 |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1789939565 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790142788, 1790142788, 1790142788 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790130905, 1790130905, 1790130905 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1789904865 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790112153, 1790112153, 1790112153 |
| Red Hat | Red Hat OpenShift Container Platform 4 |
Timeline
- Sep 23, 2026 Coalition ESS Score
- Sep 23, 2026 CVE Published
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 1, 2026 EPSS Score
- Oct 1, 2026 CVE Updated
- Oct 2, 2026 EPSS Score
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
References
- RHSA-2026:70587 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:70617 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71447 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71450 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71453 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71454 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2517886 issue-trackingx_refsource_REDHAT