VDB
CVE-2026-75887
CVE-2026-75887
PUBLISHED
CVSS 7.5 HIGH
Reported by redhat · Published September 23, 2026
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1790102793 |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1789939565 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1789904865 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790095950 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790112153 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790142788 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790130905 |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 1789939565 |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 1790102793 |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 1789904865 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790130905, 1790130905, 1790130905 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790112153, 1790112153, 1790112153 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790142788, 1790142788, 1790142788 |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790095950, 1790095950 |
Timeline
- Sep 23, 2026 CVE Published
- Sep 24, 2026 EPSS Score
- Sep 24, 2026 Coalition ESS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 1, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
- Oct 2, 2026 Distribution Patch
References
- RHSA-2026:70587 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:70617 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:70647 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71447 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71450 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71453 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:71454 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2517889 issue-trackingx_refsource_REDHAT