CVE-2026-92745: Invocation of Process Using Visible Sensitive Information in Red Hat Red Hat Enterprise Linux 10
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
AI Analysis
Technical Summary
CVE-2026-92745 is a local information disclosure vulnerability in the cockpit-machines component of Red Hat Enterprise Linux 10. It occurs because the RHSM offline token is passed as a command-line argument to a helper script during token validation, making it visible in process metadata. A local attacker with the ability to inspect process metadata during the validation process can disclose this sensitive token. The vulnerability requires local access, low privileges, and user interaction, and is contingent on the system not having restrictive /proc visibility settings. The disclosed token can be used to request access tokens, leading to confidentiality compromise. The CVSS v3.1 base score is 5.0 (medium severity) with a vector of AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N.
Potential Impact
The vulnerability allows a local attacker to disclose a sensitive RHSM offline token by inspecting process metadata. This token disclosure can lead to compromise of confidentiality because the token can be used to request further access tokens. There is no impact on integrity or availability. Exploitation requires local access and the ability to inspect process metadata during the token validation process.
Mitigation Recommendations
Red Hat has published an advisory for CVE-2026-92745 but does not explicitly state that a fix is available yet. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-92745 for current remediation guidance. Mitigation includes ensuring restrictive /proc visibility settings to prevent unauthorized process metadata inspection. Since exploitation requires local access and process metadata visibility, restricting these can reduce risk.
CVE-2026-92745: Invocation of Process Using Visible Sensitive Information in Red Hat Red Hat Enterprise Linux 10
Description
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
CVSS v3.1
Score 5.0medium
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92745 is a local information disclosure vulnerability in the cockpit-machines component of Red Hat Enterprise Linux 10. It occurs because the RHSM offline token is passed as a command-line argument to a helper script during token validation, making it visible in process metadata. A local attacker with the ability to inspect process metadata during the validation process can disclose this sensitive token. The vulnerability requires local access, low privileges, and user interaction, and is contingent on the system not having restrictive /proc visibility settings. The disclosed token can be used to request access tokens, leading to confidentiality compromise. The CVSS v3.1 base score is 5.0 (medium severity) with a vector of AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N.
Potential Impact
The vulnerability allows a local attacker to disclose a sensitive RHSM offline token by inspecting process metadata. This token disclosure can lead to compromise of confidentiality because the token can be used to request further access tokens. There is no impact on integrity or availability. Exploitation requires local access and the ability to inspect process metadata during the token validation process.
Mitigation Recommendations
Red Hat has published an advisory for CVE-2026-92745 but does not explicitly state that a fix is available yet. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-92745 for current remediation guidance. Mitigation includes ensuring restrictive /proc visibility settings to prevent unauthorized process metadata inspection. Since exploitation requires local access and process metadata visibility, restricting these can reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-16T18:40:00.345Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-92745","vendor":"Red Hat"}]
Threat ID: 6aad7cac55bf5e2cf55a40b0
Added to database: 09/18/2026, 18:02:20 UTC
Last enriched: 09/18/2026, 18:17:30 UTC
Last updated: 09/19/2026, 05:01:24 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.