PatchSiren cyber security CVE debrief
CVE-2026-71474 Red Hat CVE debrief
A local user with access to pod logs on the hub could read the long-lived credential for cloud.openshift.com, potentially granting unauthorized access to Red Hat cloud services. This vulnerability in insights-client logs request headers, including the cloud.openshift.com pull-secret token, in case of a non-200 response. The exposure of sensitive credentials in logs poses a significant risk to Red Hat cloud services. System administrators and security teams should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record and NVD entry provide details about the vulnerability.
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-09-05
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-09-05
Who should care
System administrators and security teams managing Red Hat environments, particularly those using insights-client and having access to pod logs, should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The insights-client application logs request headers in case of a non-200 response, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential, potentially granting unauthorized access to Red Hat cloud services. The vulnerability highlights the importance of proper logging controls and sensitive information protection in insights-client. It is crucial for system administrators and security teams to review and restrict access to pod logs, implement additional logging controls, and rotate the cloud.openshift.com pull-secret token for all affected systems.
Defensive priority
Medium-priority defensive actions are required to address the potential unauthorized access to Red Hat cloud services via the exposure of the cloud.openshift.com pull-secret token in insights-client logs.
Recommended defensive actions
- Review and restrict access to pod logs on the hub to prevent unauthorized users from reading sensitive credentials.
- Implement additional logging controls to prevent the inclusion of sensitive information like the cloud.openshift.com pull-secret token in logs.
- Rotate and update the cloud.openshift.com pull-secret token for all affected systems as a precautionary measure.
- Monitor for any suspicious activity related to the exposure of the cloud.openshift.com pull-secret token.
- Consider implementing compensating controls, such as IP restrictions or additional authentication mechanisms, to protect Red Hat cloud services.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability in insights-client, which logs request headers, including the cloud.openshift.com pull-secret token, in case of a non-200 response. A local user with access to pod logs could read this long-lived credential.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71474 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71474
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71474 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71474
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-71474
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.