CVE-2026-75887: Red Hat Openshift Container Platform 4.12

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.

Affected products

  • Red Hat Red Hat Openshift Container Platform 4.12: before 1790102793 (fixed in 1790102793)
  • Red Hat Red Hat Openshift Container Platform 4.14: before 1790606051 (fixed in 1790606051)
  • Red Hat Red Hat Openshift Container Platform 4.16: before 1790636171 (fixed in 1790636171)
  • Red Hat Red Hat Openshift Container Platform 4.17: before 1789939565 (fixed in 1789939565)
  • Red Hat Red Hat Openshift Container Platform 4.18: before 1789904865 (fixed in 1789904865)
  • Red Hat Red Hat Openshift Container Platform 4.19: before 1790095950 (fixed in 1790095950)
  • Red Hat Red Hat Openshift Container Platform 4.20: before 1790112153 (fixed in 1790112153)
  • Red Hat Red Hat Openshift Container Platform 4.21: before 1790142788 (fixed in 1790142788)
  • Red Hat Red Hat Openshift Container Platform 4.22: before 1790130905 (fixed in 1790130905)

Published 2026-09-23. Last modified 2026-10-08.