Skip to main content

CVE-2026-75887: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat OpenShift Container Platform 4

0
High
VulnerabilityCVE-2026-75887cvecve-2026-75887
Published: 09/23/2026 (09/23/2026, 21:24:01 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat OpenShift Container Platform 4

Description

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected software

Red Hat

Red Hat OpenShift Container Platform 4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 21:47:47 UTC

Technical Analysis

This vulnerability exists in the OpenShift console's internationalization (i18n) locale handler. By exploiting a path traversal flaw in the /locales/resource.json endpoint via the lng and ns query parameters, an unauthenticated attacker can read sensitive JSON files from the pod filesystem, including plugin manifests and configuration files. The flaw also affects registered dynamic-plugin backends, potentially increasing information disclosure in default OpenShift Container Platform deployments. Red Hat has classified this vulnerability as Important and rated it with a CVSS v3.1 score of 7.5 (high severity). No official fix or mitigation currently meets Red Hat's standards for deployment and stability. The vulnerability is tracked as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).

Potential Impact

An unauthenticated attacker can read sensitive JSON files from the pod filesystem, including plugin manifests and configuration files, potentially exposing confidential configuration data. This information disclosure could facilitate further attacks or bypass security mechanisms. The vulnerability does not impact integrity or availability directly but poses a significant confidentiality risk.

Mitigation Recommendations

Red Hat currently does not provide a mitigation or patch that meets their criteria for ease of use, applicability, or stability. Users should monitor the Red Hat advisory for updates. Until a fix is available, consider restricting access to the OpenShift console and limiting exposure of the /locales/resource.json endpoint where possible. Engage with Red Hat support or a Technical Account Manager for guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-08-18T13:44:59.078Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-75887","vendor":"Red Hat"}]

Threat ID: 6ab445a0f7a7c541065c1c80

Added to database: 09/23/2026, 21:33:20 UTC

Last enriched: 09/23/2026, 21:47:47 UTC

Last updated: 09/24/2026, 01:57:04 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses