CVE-2026-75887: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat OpenShift Container Platform 4
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.
AI Analysis
Technical Summary
This vulnerability exists in the OpenShift console's internationalization (i18n) locale handler. By exploiting a path traversal flaw in the /locales/resource.json endpoint via the lng and ns query parameters, an unauthenticated attacker can read sensitive JSON files from the pod filesystem, including plugin manifests and configuration files. The flaw also affects registered dynamic-plugin backends, potentially increasing information disclosure in default OpenShift Container Platform deployments. Red Hat has classified this vulnerability as Important and rated it with a CVSS v3.1 score of 7.5 (high severity). No official fix or mitigation currently meets Red Hat's standards for deployment and stability. The vulnerability is tracked as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).
Potential Impact
An unauthenticated attacker can read sensitive JSON files from the pod filesystem, including plugin manifests and configuration files, potentially exposing confidential configuration data. This information disclosure could facilitate further attacks or bypass security mechanisms. The vulnerability does not impact integrity or availability directly but poses a significant confidentiality risk.
Mitigation Recommendations
Red Hat currently does not provide a mitigation or patch that meets their criteria for ease of use, applicability, or stability. Users should monitor the Red Hat advisory for updates. Until a fix is available, consider restricting access to the OpenShift console and limiting exposure of the /locales/resource.json endpoint where possible. Engage with Red Hat support or a Technical Account Manager for guidance.
CVE-2026-75887: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat OpenShift Container Platform 4
Description
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.
CVSS v3.1
Score 7.5high
Affected software
Red Hat
Red Hat OpenShift Container Platform 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the OpenShift console's internationalization (i18n) locale handler. By exploiting a path traversal flaw in the /locales/resource.json endpoint via the lng and ns query parameters, an unauthenticated attacker can read sensitive JSON files from the pod filesystem, including plugin manifests and configuration files. The flaw also affects registered dynamic-plugin backends, potentially increasing information disclosure in default OpenShift Container Platform deployments. Red Hat has classified this vulnerability as Important and rated it with a CVSS v3.1 score of 7.5 (high severity). No official fix or mitigation currently meets Red Hat's standards for deployment and stability. The vulnerability is tracked as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).
Potential Impact
An unauthenticated attacker can read sensitive JSON files from the pod filesystem, including plugin manifests and configuration files, potentially exposing confidential configuration data. This information disclosure could facilitate further attacks or bypass security mechanisms. The vulnerability does not impact integrity or availability directly but poses a significant confidentiality risk.
Mitigation Recommendations
Red Hat currently does not provide a mitigation or patch that meets their criteria for ease of use, applicability, or stability. Users should monitor the Red Hat advisory for updates. Until a fix is available, consider restricting access to the OpenShift console and limiting exposure of the /locales/resource.json endpoint where possible. Engage with Red Hat support or a Technical Account Manager for guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-18T13:44:59.078Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-75887","vendor":"Red Hat"}]
Threat ID: 6ab445a0f7a7c541065c1c80
Added to database: 09/23/2026, 21:33:20 UTC
Last enriched: 09/23/2026, 21:47:47 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.