PatchSiren cyber security CVE debrief
CVE-2026-75887 Red Hat CVE debrief
An unauthenticated path traversal vulnerability was found in the OpenShift console, allowing an attacker to read sensitive *.json files from the pod filesystem. This flaw can enable path traversal against registered dynamic-plugin backends. The vulnerability exists due to insufficient input validation in the `/locales/resource.json` endpoint, which can be exploited by manipulating the `lng` and `ns` query parameters. As a result, an attacker may access sensitive information, including plugin manifests and configuration files. Defenders should assess exposure and apply patches or mitigations to prevent potential sensitive file reads and path traversal attacks.
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4.12
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for OpenShift console configurations, plugin manifests, and dynamic-plugin backends should assess exposure and apply patches or mitigations to prevent potential sensitive file reads.
Why it matters
Unauthenticated path traversal in OpenShift console allows sensitive file reads and potential path traversal against dynamic-plugin backends, requiring defenders to verify exposure and apply patches or mitigations.
- Potential sensitive file reads from the pod filesystem
- Possible path traversal against registered dynamic-plugin backends
- Verification of exposure and patch application priority
- Monitoring for suspicious activity related to dynamic-plugin backends
Technical summary
The OpenShift console is vulnerable to an unauthenticated path traversal attack, allowing an attacker to read sensitive *.json files from the pod filesystem by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This vulnerability can be exploited to access sensitive information, including plugin manifests and configuration files. The attack can also enable path traversal against registered dynamic-plugin backends, potentially leading to further exploitation. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent potential sensitive file reads and path traversal attacks. The vulnerability is a result of insufficient input validation,
Defensive priority
Defenders should prioritize verifying exposure and applying patches or mitigations to prevent potential sensitive file reads.
Recommended defensive actions
- Verify exposure by checking OpenShift console configurations and plugin manifests
- Apply patches or mitigations provided by Red Hat
- Monitor for suspicious activity related to dynamic-plugin backends
- Review and update incident response plans to address potential sensitive file reads
- Perform a thorough review of the OpenShift console and dynamic-plugin backends for any signs of compromise
- Implement additional security measures, such as Web Application Firewalls (WAFs), to detect and prevent similar attacks
- Conduct regular security audits and vulnerability assessments to identify and address potential weaknesses
Evidence notes
The CVE record and source item provide details on the vulnerability, but do not specify which versions are affected or provide remediation steps. Red Hat has released several advisories related to this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75887 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75887
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75887 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75887
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/75xxx/CVE-2026-75887.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70587
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70617
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:70647
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:71447
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:71450
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:71453
Supplemental source - vendor-advisory, x_refsource_REDHAT
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:71454
Supplemental source - vendor-advisory, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.