PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75887 Red Hat CVE debrief

An unauthenticated path traversal vulnerability was found in the OpenShift console, allowing an attacker to read sensitive *.json files from the pod filesystem. This flaw can enable path traversal against registered dynamic-plugin backends. The vulnerability exists due to insufficient input validation in the `/locales/resource.json` endpoint, which can be exploited by manipulating the `lng` and `ns` query parameters. As a result, an attacker may access sensitive information, including plugin manifests and configuration files. Defenders should assess exposure and apply patches or mitigations to prevent potential sensitive file reads and path traversal attacks.

Vendor
Red Hat
Product
Red Hat OpenShift Container Platform 4.12
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-23
Original CVE updated
2026-10-08
Advisory published
2026-09-23
Advisory updated
2026-10-08

Who should care

Defenders responsible for OpenShift console configurations, plugin manifests, and dynamic-plugin backends should assess exposure and apply patches or mitigations to prevent potential sensitive file reads.

Why it matters

Unauthenticated path traversal in OpenShift console allows sensitive file reads and potential path traversal against dynamic-plugin backends, requiring defenders to verify exposure and apply patches or mitigations.

  • Potential sensitive file reads from the pod filesystem
  • Possible path traversal against registered dynamic-plugin backends
  • Verification of exposure and patch application priority
  • Monitoring for suspicious activity related to dynamic-plugin backends

Technical summary

The OpenShift console is vulnerable to an unauthenticated path traversal attack, allowing an attacker to read sensitive *.json files from the pod filesystem by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This vulnerability can be exploited to access sensitive information, including plugin manifests and configuration files. The attack can also enable path traversal against registered dynamic-plugin backends, potentially leading to further exploitation. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent potential sensitive file reads and path traversal attacks. The vulnerability is a result of insufficient input validation,

Defensive priority

Defenders should prioritize verifying exposure and applying patches or mitigations to prevent potential sensitive file reads.

Recommended defensive actions

  • Verify exposure by checking OpenShift console configurations and plugin manifests
  • Apply patches or mitigations provided by Red Hat
  • Monitor for suspicious activity related to dynamic-plugin backends
  • Review and update incident response plans to address potential sensitive file reads
  • Perform a thorough review of the OpenShift console and dynamic-plugin backends for any signs of compromise
  • Implement additional security measures, such as Web Application Firewalls (WAFs), to detect and prevent similar attacks
  • Conduct regular security audits and vulnerability assessments to identify and address potential weaknesses

Evidence notes

The CVE record and source item provide details on the vulnerability, but do not specify which versions are affected or provide remediation steps. Red Hat has released several advisories related to this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75887 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75887

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75887 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75887

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/75xxx/CVE-2026-75887.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70587

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70617

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:70647

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:71447

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:71450

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:71453

    Supplemental source - vendor-advisory, x_refsource_REDHAT

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:71454

    Supplemental source - vendor-advisory, x_refsource_REDHAT

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.