CVE-2026-71474: Red Hat Advanced Cluster Management For Kubernetes
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.
Affected products
- Red Hat Advanced Cluster Management For Kubernetes: version 2.0 only
- Red Hat Insights-Client: affected versions not specified
Published 2026-08-11. Last modified 2026-09-05.