CVE-2026-71474: Red Hat Advanced Cluster Management For Kubernetes

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.

Affected products

  • Red Hat Advanced Cluster Management For Kubernetes: version 2.0 only
  • Red Hat Insights-Client: affected versions not specified

Published 2026-08-11. Last modified 2026-09-05.